Skip to content

Bump brakeman from 8.0.6 to 8.1.0 - #2727

Merged
govuk-ci merged 1 commit into
mainfrom
dependabot/bundler/brakeman-8.1.0
Oct 5, 2026
Merged

govuk-ci merged 1 commit into
mainfrom
dependabot/bundler/brakeman-8.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps brakeman from 8.0.6 to 8.1.0.

Release notes

Sourced from brakeman's releases.

8.1.0

  • Update SonarQube report to use generic issue format (@​fffx)
  • Include regex code in validation warnings (@​eliotsykes)
  • Check validation regexes in non-activerecord models (@​eliotsykes)
  • Skip top-level vendor directory before recursive globbing (@​ronocod)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (@​cubasepp / @​Eljees)
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (@​Eljees)
  • Fix frozen string error (@​shaicoleman)
  • Better help and error message for --ensure-latest (#2036)
Changelog

Sourced from brakeman's changelog.

8.1.0 - 2026-09-30

  • Better help and error message for --ensure-latest
  • Fix frozen string error (Shai Coleman)
  • Update Sonar report format (fangxing)
  • Fix frozen src string error
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (Yuriy Tumanov)
  • Include regex code in validation warnings (Eliot Sykes)
  • Check validation regexes in non-activerecord models (Eliot Sykes)
  • Skip top-level vendor directory before recursive globbing (Conor O'Donnell)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (Michael Vogl/Yuriy Tumanov)
Commits
  • c778164 Bump to 8.1.0
  • 4621407 Update CHANGES
  • 26ba01f Support Rails 7.1+ positional enum syntax in SQL injection check (#2051)
  • 8f04922 Skip top-level vendor directory before recursive globbing (#2039)
  • f921f01 Check validation regexes in non-activerecord models (#2053)
  • d62e919 Fix CheckValidationRegex overly broad ignores (#2050)
  • 73bbc99 Recognize Haml::AttributeBuilder.build_class as an escaped output (#2052)
  • 71f8f69 Fix typo in test_format_validation_with_multiline (#2049)
  • 0fd4dbc Add bundle install step to contributing doc (#2047)
  • 5de415c Fix ERB frozen src error (#2048)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [brakeman](https://github.com/presidentbeef/brakeman) from 8.0.6 to 8.1.0.
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](presidentbeef/brakeman@v8.0.6...v8.1.0)

---
updated-dependencies:
- dependency-name: brakeman
  dependency-version: 8.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies ruby Pull requests that update Ruby code labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

⚠️ This repo is Continuously Deployed: make sure you follow the guidance ⚠️

Follow these steps if you are doing a Rails upgrade.

@govuk-ci govuk-ci left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR has been scanned and automatically approved by govuk-dependabot-merger.

@govuk-ci
govuk-ci merged commit 190a32a into main Oct 5, 2026
10 checks passed
@govuk-ci
govuk-ci deleted the dependabot/bundler/brakeman-8.1.0 branch October 5, 2026 08:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant