Skip to content

chore(deps): update dependency brakeman to v8 - #608

Open
renovate[bot] wants to merge 1 commit into
stagingfrom
renovate/brakeman-8.x
Open

renovate[bot] wants to merge 1 commit into
stagingfrom
renovate/brakeman-8.x

Conversation

@renovate

@renovate renovate Bot commented Jan 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
brakeman (source, changelog) '~> 7.1' → '~> 8.0', '>= 8.0.6' age confidence

Release Notes

presidentbeef/brakeman (brakeman)

v8.0.6

Compare Source

  • Fix EOL date for Rails 8.0 (yeaseul-kim)
  • Add EOL dates for Rails 8.1 and Ruby 4.0
  • Fix command injection false positives (Jacob Evelyn)
  • Fix unused variable warning (viralpraxis)

v8.0.5

Compare Source

  • Add quote_schema_name to safe quote method list (Zsolt Kozaroczy)
  • Fix SQL injection false positive for compact_blank/compact on permitted params (Arpit Jain)
  • Fix inline render false positive for local named text (Arpit Jain)
  • Fix HAML crash on .raw calls (Federico Franco)
  • Fix Ruby version parsing - especially for non-CRuby versions (Chris Southerland Jr)
  • Fix TemplateAliasProcessor#template_name arity (viralpraxis)
  • Reduce false positives when using shell escaping

v8.0.4

Compare Source

  • Load 'date' library for --ensure-latest

v8.0.3

Compare Source

  • Fix polymorphic_name SQLi false positive (Fredrico Franco)
  • Fix logger behavior when loading config files
  • Handle application names with module prefixes
  • Add release age option for --ensure-latest

v8.0.2

Compare Source

  • Reline console control should use stderr
  • Fix logger cleanup based method (Imran Iqbal)

v8.0.1

Compare Source

  • Make sure to reset the cursor even when exit code is 0

v8.0.0

Compare Source

  • No longer produce weak dynamic render path warnings
  • --skip-libs removed
  • --index-libs removed
  • Revamp of scan progress output and logging
  • Faster file globbing for templates (Mikael Henriksson)
  • Fix singleton method prefixes (viralpraxis)
  • Fix qualified constant lookup to respect module/class context (Mike Dalessio)
  • Replace Erubis with Erubi

v7.1.2

Compare Source

  • Update ruby_parser to remove version restriction (Chedli Bourguiba)
  • Raise minimum required Ruby to 3.2.0
  • Use Minitest 6.0
  • Reduce SQL injection false positives from count calls
  • Ignore more Haml attribute builder methods

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jan 29, 2026
@coderabbitai

coderabbitai Bot commented Jan 29, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 330a7282-afe0-425d-a197-6dfbb070552e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Jan 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.92%. Comparing base (27e4306) to head (f7b248e).

Additional details and impacted files
@@           Coverage Diff            @@
##           staging     #608   +/-   ##
========================================
  Coverage    99.92%   99.92%           
========================================
  Files          200      200           
  Lines         2700     2700           
========================================
  Hits          2698     2698           
  Misses           2        2           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate
renovate Bot force-pushed the renovate/brakeman-8.x branch 2 times, most recently from 0f4957c to ba066e3 Compare February 3, 2026 21:55
@renovate
renovate Bot force-pushed the renovate/brakeman-8.x branch 2 times, most recently from ee7298d to e9a4e9b Compare February 27, 2026 04:53
@renovate
renovate Bot force-pushed the renovate/brakeman-8.x branch from e9a4e9b to 59d6ff7 Compare May 18, 2026 20:53
@renovate
renovate Bot force-pushed the renovate/brakeman-8.x branch from 59d6ff7 to 84afbd7 Compare June 13, 2026 02:02
@renovate
renovate Bot force-pushed the renovate/brakeman-8.x branch from 84afbd7 to 240be42 Compare August 13, 2026 04:05
@renovate
renovate Bot force-pushed the renovate/brakeman-8.x branch 3 times, most recently from bd42337 to da6c13f Compare September 7, 2026 22:48
@renovate
renovate Bot force-pushed the renovate/brakeman-8.x branch from da6c13f to f7b248e Compare September 15, 2026 11:43

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants