Skip to content

build(deps): bump rails and acts_as_paranoid - #326

Open
dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/bundler/multi-0db574f8d2
Open

dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/bundler/multi-0db574f8d2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 6, 2026

Copy link
Copy Markdown
Contributor

Bumps rails and acts_as_paranoid. These dependencies needed to be updated together.
Updates rails from 8.0.5.1 to 8.1.3.1

Release notes

Sourced from rails's releases.

8.1.3.1

Active Support

  • No changes.

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • No changes.

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Disable libvips's unfuzzed image loaders and savers.

    libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only safe for trusted content. Active Storage will call Vips.block_untrusted(true) to disable them while booting. An application that needs a specific loader or saver may re-enable it in an initializer.

... (truncated)

Commits
  • 3989ebf Preparing for 8.1.3.1 release
  • 349e7a5 Disable libvips's unfuzzed image loaders and savers
  • fa8f081 Preparing for 8.1.3 release
  • 63cef3d Merge branch '8-1-sec' into 8-1-stable
  • 1db4b89 Preparing for 8.1.2.1 release
  • 1c7d1cf Update changelog
  • e91694b Update CHANGELOG (8.1 only)
  • 6752711 Fix XSS in debug exceptions copy-to-clipboard
  • 63f5ad8 Skip blank attribute names in Action View tag helpers
  • 8c9676b Prevent glob injection in ActiveStorage DiskService#delete_prefixed
  • Additional commits viewable in compare view

Updates acts_as_paranoid from 0.10.3 to 0.11.0

Changelog

Sourced from acts_as_paranoid's changelog.

0.11.0

  • Support Ruby 3.1 through 3.4, dropping support for Ruby 3.0 (#359 by [mvz])
  • Support Rails 8.1 (#368 by [fatkodima])

#359: ActsAsParanoid/acts_as_paranoid#359 #368: ActsAsParanoid/acts_as_paranoid#368

Commits
  • 6bf8906 Prepare version 0.11.0 for release
  • d1547c8 Merge pull request #368 from fatkodima/rails-8-1
  • dac1468 Support Rails 8.1
  • c07598e Merge pull request #366 from ActsAsParanoid/dependabot/github_actions/actions...
  • d50a85a Bump actions/checkout from 4 to 5
  • d079aae Merge pull request #365 from ActsAsParanoid/fix-rubocop-offenses
  • 9a42ae4 Regenerate RuboCop to-do file
  • 2b6c1a8 Autocorrect Style/RedundantParentheses
  • 727b1e6 Use the new rubocop plugins configuration syntax
  • 9446644 Bump rubocop dependencies
  • Additional commits viewable in compare view

dependabot Bot added 7 commits September 6, 2026 11:53
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 6, 2026
@socket-security

socket-security Bot commented Sep 6, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgem/​rails@​8.0.5.1 ⏵ 8.1.3.110010090100100
Updatedgem/​acts_as_paranoid@​0.10.3 ⏵ 0.11.0100100100100100

View full report

@socket-security

socket-security Bot commented Sep 6, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: gem actionpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: Gemfile.lockgem/rails_semantic_logger@4.19.0gem/vite_rails@3.0.20gem/public_activity@3.0.2gem/phlex-rails@2.4.0gem/good_job@4.13.3gem/web-console@4.3.0gem/rails@8.1.3.1gem/premailer-rails@1.12.0gem/wicked@2.0.0gem/letter_opener_web@3.0.0gem/rspec-rails@7.1.1gem/audits1984@0.1.7gem/doorkeeper@5.8.2gem/active_storage_encryption@0.3.0gem/factory_bot_rails@6.5.1gem/propshaft@1.3.1gem/sentry-rails@5.28.1gem/cloudflare-rails@7.0.0gem/actionpack@8.1.3.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore gem/actionpack@8.1.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: gem activerecord is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: Gemfile.lockgem/public_activity@3.0.2gem/annotaterb@4.22.0gem/good_job@4.13.3gem/flipper-active_record@1.4.0gem/rails@8.1.3.1gem/kaminari@1.2.2gem/hashid-rails@1.4.1gem/paper_trail@16.0.0gem/active_storage_encryption@0.3.0gem/acts_as_paranoid@0.11.0gem/activerecord@8.1.3.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore gem/activerecord@8.1.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: gem activerecord is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: Gemfile.lockgem/public_activity@3.0.2gem/annotaterb@4.22.0gem/good_job@4.13.3gem/flipper-active_record@1.4.0gem/rails@8.1.3.1gem/kaminari@1.2.2gem/hashid-rails@1.4.1gem/paper_trail@16.0.0gem/active_storage_encryption@0.3.0gem/acts_as_paranoid@0.11.0gem/activerecord@8.1.3.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore gem/activerecord@8.1.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

dependabot Bot added 2 commits September 6, 2026 12:23
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rails](https://github.com/rails/rails) and [acts_as_paranoid](https://github.com/ActsAsParanoid/acts_as_paranoid). These dependencies needed to be updated together.

Updates `rails` from 8.0.5.1 to 8.1.3.1
- [Release notes](https://github.com/rails/rails/releases)
- [Commits](rails/rails@v8.0.5.1...v8.1.3.1)

Updates `acts_as_paranoid` from 0.10.3 to 0.11.0
- [Changelog](https://github.com/ActsAsParanoid/acts_as_paranoid/blob/master/CHANGELOG.md)
- [Commits](ActsAsParanoid/acts_as_paranoid@v0.10.3...v0.11.0)

---
updated-dependencies:
- dependency-name: acts_as_paranoid
  dependency-version: 0.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: rails
  dependency-version: 8.1.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/multi-0db574f8d2 branch from 3761774 to b26469a Compare September 6, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants