Skip to content

Bump dependencies: rails, lucide-rails, ruby_ui, pnpm/action-setup, docker/login-action#444

Merged
djalmaaraujo merged 9 commits intomainfrom
dependabot/combined-updates
Apr 1, 2026
Merged

Bump dependencies: rails, lucide-rails, ruby_ui, pnpm/action-setup, docker/login-action#444
djalmaaraujo merged 9 commits intomainfrom
dependabot/combined-updates

Conversation

@djalmaaraujo
Copy link
Copy Markdown
Contributor

Summary

Combines all open Dependabot PRs into a single update:

  • rails 8.1.2 → 8.1.3 — security fixes (XSS in debug exceptions, path traversal in ActiveStorage) + bugfixes
  • lucide-rails 0.7.3 → 0.7.4 — fix ActiveSupport.on_load in railtie to avoid premature ActionView load
  • ruby_ui 755b288856136f — adds bun package manager support
  • pnpm/action-setup 4 → 5 — updated to Node.js 24 runtime
  • docker/login-action 3 → 4 — updated to Node.js 24 runtime

Closes

Supersedes #439, #440, #441, #442, #443

Test plan

  • CI passes
  • Verify app boots in Docker container
  • Smoke test docs pages

dependabot bot and others added 9 commits March 30, 2026 04:56
Bumps [ruby_ui](https://github.com/ruby-ui/ruby_ui) from `755b288` to `856136f`.
- [Release notes](https://github.com/ruby-ui/ruby_ui/releases)
- [Commits](ruby-ui/ruby_ui@755b288...856136f)

---
updated-dependencies:
- dependency-name: ruby_ui
  dependency-version: 856136f40bc4d5be942e39506e56fb08348afc93
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [lucide-rails](https://github.com/heyvito/lucide-rails) from 0.7.3 to 0.7.4.
- [Release notes](https://github.com/heyvito/lucide-rails/releases)
- [Changelog](https://github.com/heyvito/lucide-rails/blob/master/CHANGELOG.md)
- [Commits](https://github.com/heyvito/lucide-rails/commits/v0.7.4)

---
updated-dependencies:
- dependency-name: lucide-rails
  dependency-version: 0.7.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rails](https://github.com/rails/rails) from 8.1.2 to 8.1.3.
- [Release notes](https://github.com/rails/rails/releases)
- [Commits](rails/rails@v8.1.2...v8.1.3)

---
updated-dependencies:
- dependency-name: rails
  dependency-version: 8.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [docker/login-action](https://github.com/docker/login-action) from 3 to 4.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v3...v4)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 4 to 5.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@v4...v5)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…/login-action-4' into dependabot/combined-updates
@djalmaaraujo djalmaaraujo requested a review from cirdes as a code owner April 1, 2026 11:28
@djalmaaraujo djalmaaraujo merged commit 402c795 into main Apr 1, 2026
3 checks passed
@djalmaaraujo djalmaaraujo deleted the dependabot/combined-updates branch April 1, 2026 11:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant