Skip to content

chore(deps): bump the ruby-deps group with 7 updates - #2995

Merged
mroderick merged 1 commit into
masterfrom
dependabot/bundler/ruby-deps-95bdeb6933
Oct 8, 2026
Merged

mroderick merged 1 commit into
masterfrom
dependabot/bundler/ruby-deps-95bdeb6933

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the ruby-deps group with 7 updates:

Package From To
image_processing 2.1.0 2.2.0
icalendar 2.12.4 2.12.5
tzinfo-data 1.2026.4 1.2026.5
capybara-playwright-driver 0.5.10 0.5.12
simplecov 1.3.0 1.3.2
scout_apm 6.3.0 6.3.1
prawn-svg 0.40.3 0.40.4

Updates image_processing from 2.1.0 to 2.2.0

Changelog

Sourced from image_processing's changelog.

2.2.0 (2026-09-29)

  • Save in the #convert format when the destination path has no extension, such as a /dev/fd/N path (thanks to @​flavorjones)
Commits
  • d9737fb Set version to 2.2.0
  • 8f7b538 Handle missing AVIF encoder in tests
  • 92086c5 Handle AVIF format on extensionless destinations
  • 5827e83 Save in the #convert format to an extensionless destination (#150)
  • See full diff in compare view

Updates icalendar from 2.12.4 to 2.12.5

Changelog

Sourced from icalendar's changelog.

2.12.5 - 2026-09-25

  • Generate timezone transition onsets and recurrence dates using the previous UTC offset. - Ben Abulafia
  • Limit parsing depth
  • Remove TZID from DATE values - Henry Blyth
Commits
  • 0bcfef3 Bump version to 2.12.5
  • 18803f0 Merge pull request #326 from bensynapse/fix-timezone-transition-onsets
  • fdaafa5 Merge pull request #327 from icalendar/limit-parse-depth
  • c7cd145 Remove EOL ruby from testing matrix
  • 849b39a Limit how deeply nested an ics file can be
  • c68c941 Add failing test for parse depth
  • cee52d1 Fix generated timezone transition onsets
  • a085861 Merge pull request #325 from henrahmagix/patch-1
  • 1b6cc48 Delete tzid: keyword arg from DATE values
  • See full diff in compare view

Updates tzinfo-data from 1.2026.4 to 1.2026.5

Release notes

Sourced from tzinfo-data's releases.

v1.2026.5

Based on version 2026e of the IANA Time Zone Database (https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/message/VXIA4AU73OQL3OZ3ZBZHWIASIIVBGUJV/).

Commits

Updates capybara-playwright-driver from 0.5.10 to 0.5.12

Commits
  • ff26b75 0.5.12
  • 4f933a5 Merge pull request #163 from YusukeIwaki/codex/fix-firefox-refresh
  • eae2476 Wait for initial POST navigation in refresh specs
  • cb4eda9 Merge pull request #161 from YusukeIwaki/codex/preserve-visible-text-blank-lines
  • 9d394e0 Remove the dedicated refresh CI job
  • 0a23570 Identify the reloaded document before checking readiness
  • 271f201 Address visible text review feedback
  • 8dd6e55 Wait for Firefox refresh to finish loading
  • e0252aa Preserve blank lines in visible text
  • 7d08ad6 Merge pull request #160 from YusukeIwaki/codex/fix-stale-action-retries
  • Additional commits viewable in compare view

Updates simplecov from 1.3.0 to 1.3.2

Release notes

Sourced from simplecov's releases.

v1.3.2

Bugfixes

  • The HTML report is generated again on Rails 8.1.4 when a parallelize_teardown hook calls SimpleCov.result. Rails 8.1.4 runs those hooks in the parent process as well as in each worker, and collecting the result there stops Coverage, which the exit handler took as a sign that nothing was left to report. The exit handler now formats a result that was already collected. See simplecov-ruby/simplecov#1308.

v1.3.1

Bugfixes

  • cover_views compiles templates on Rails main again. Rails removed ActionView::Template.registered_template_handler; the lookup reads ActionView::Template::Handlers.template_handlers and still skips an extension with no handler. See simplecov-ruby/simplecov#1300.
  • require "simplecov" works again on JRuby on Windows, where 1.3.0 raised LoadError: Could not open library '.../libprism.dll'. Prism's FFI backend cannot open its native library there, and 1.3.0 required Prism as soon as SimpleCov loaded. Prism now loads only when branch or method coverage needs the static extractor, which a line-only run never does. Where it cannot load at all, the extractor falls back to empty branch and method tables for never-loaded files, as it did before 1.3.0. See simplecov-ruby/simplecov#1299.
  • simplecov affected --run works on JRuby on Windows, where it crashed with NoMethodError because Process.wait2 answers no status there. On that platform the runner starts through Kernel#system instead.
  • simplecov serve refuses a symlink that points outside the report on JRuby on Windows too. JRuby's File.realpath follows no symlinks there, so serve would have served the file the link pointed to, and simplecov clean and the coverage.json lookup compared paths that were never resolved. On JRuby the CLI now resolves paths through the JDK.
Changelog

Sourced from simplecov's changelog.

1.3.2 (2026-09-30)

Bugfixes

  • The HTML report is generated again on Rails 8.1.4 when a parallelize_teardown hook calls SimpleCov.result. Rails 8.1.4 runs those hooks in the parent process as well as in each worker, and collecting the result there stops Coverage, which the exit handler took as a sign that nothing was left to report. The exit handler now formats a result that was already collected. See simplecov-ruby/simplecov#1308.

1.3.1 (2026-09-24)

Bugfixes

  • cover_views compiles templates on Rails main again. Rails removed ActionView::Template.registered_template_handler; the lookup reads ActionView::Template::Handlers.template_handlers and still skips an extension with no handler. See simplecov-ruby/simplecov#1300.
  • require "simplecov" works again on JRuby on Windows, where 1.3.0 raised LoadError: Could not open library '.../libprism.dll'. Prism's FFI backend cannot open its native library there, and 1.3.0 required Prism as soon as SimpleCov loaded. Prism now loads only when branch or method coverage needs the static extractor, which a line-only run never does. Where it cannot load at all, the extractor falls back to empty branch and method tables for never-loaded files, as it did before 1.3.0. See simplecov-ruby/simplecov#1299.
  • simplecov affected --run works on JRuby on Windows, where it crashed with NoMethodError because Process.wait2 answers no status there. On that platform the runner starts through Kernel#system instead.
  • simplecov serve refuses a symlink that points outside the report on JRuby on Windows too. JRuby's File.realpath follows no symlinks there, so serve would have served the file the link pointed to, and simplecov clean and the coverage.json lookup compared paths that were never resolved. On JRuby the CLI now resolves paths through the JDK.
Commits
  • 52a8754 Bump version to 1.3.2
  • 4fb4ae1 Format a result collected before exit on Rails 8.1.4
  • 1476741 bundle update
  • 343a933 Stop leaking a flush thread in the forked-child production specs
  • e64fcaa Bump ruby/setup-ruby from 1.323.0 to 1.325.0
  • cb8bd83 Bump oxlint from 1.83.0 to 1.85.0 in /html_frontend
  • 4ee7894 Bump version to 1.3.1
  • 486e55e bundle update
  • d2a62a8 Resolve paths and wait on runners correctly on JRuby on Windows
  • 3a2e08e Load Prism only when the static extractor runs
  • Additional commits viewable in compare view

Updates scout_apm from 6.3.0 to 6.3.1

Changelog

Sourced from scout_apm's changelog.

6.3.1

  • Capture route names for Grape 4 (#635)
Commits

Updates prawn-svg from 0.40.3 to 0.40.4

Release notes

Sourced from prawn-svg's releases.

v0.40.4

What's Changed

New Contributors

Full Changelog: mogest/prawn-svg@v0.40.3...v0.40.4

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the ruby-deps group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [image_processing](https://github.com/janko/image_processing) | `2.1.0` | `2.2.0` |
| [icalendar](https://github.com/icalendar/icalendar) | `2.12.4` | `2.12.5` |
| [tzinfo-data](https://github.com/tzinfo/tzinfo-data) | `1.2026.4` | `1.2026.5` |
| [capybara-playwright-driver](https://github.com/YusukeIwaki/capybara-playwright-driver) | `0.5.10` | `0.5.12` |
| [simplecov](https://github.com/simplecov-ruby/simplecov) | `1.3.0` | `1.3.2` |
| [scout_apm](https://github.com/scoutapp/scout_apm_ruby) | `6.3.0` | `6.3.1` |
| [prawn-svg](https://github.com/mogest/prawn-svg) | `0.40.3` | `0.40.4` |


Updates `image_processing` from 2.1.0 to 2.2.0
- [Changelog](https://github.com/janko/image_processing/blob/master/CHANGELOG.md)
- [Commits](janko/image_processing@v2.1.0...v2.2.0)

Updates `icalendar` from 2.12.4 to 2.12.5
- [Changelog](https://github.com/icalendar/icalendar/blob/main/CHANGELOG.md)
- [Commits](icalendar/icalendar@v2.12.4...v2.12.5)

Updates `tzinfo-data` from 1.2026.4 to 1.2026.5
- [Release notes](https://github.com/tzinfo/tzinfo-data/releases)
- [Commits](tzinfo/tzinfo-data@v1.2026.4...v1.2026.5)

Updates `capybara-playwright-driver` from 0.5.10 to 0.5.12
- [Commits](YusukeIwaki/capybara-playwright-driver@0.5.10...0.5.12)

Updates `simplecov` from 1.3.0 to 1.3.2
- [Release notes](https://github.com/simplecov-ruby/simplecov/releases)
- [Changelog](https://github.com/simplecov-ruby/simplecov/blob/main/CHANGELOG.md)
- [Commits](simplecov-ruby/simplecov@v1.3.0...v1.3.2)

Updates `scout_apm` from 6.3.0 to 6.3.1
- [Changelog](https://github.com/scoutapp/scout_apm_ruby/blob/master/CHANGELOG.markdown)
- [Commits](scoutapp/scout_apm_ruby@v6.3.0...v6.3.1)

Updates `prawn-svg` from 0.40.3 to 0.40.4
- [Release notes](https://github.com/mogest/prawn-svg/releases)
- [Commits](mogest/prawn-svg@v0.40.3...v0.40.4)

---
updated-dependencies:
- dependency-name: image_processing
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ruby-deps
- dependency-name: icalendar
  dependency-version: 2.12.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: tzinfo-data
  dependency-version: 1.2026.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: capybara-playwright-driver
  dependency-version: 0.5.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: simplecov
  dependency-version: 1.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: scout_apm
  dependency-version: 6.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
- dependency-name: prawn-svg
  dependency-version: 0.40.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ruby-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies ruby Pull requests that update Ruby code labels Oct 8, 2026

@mroderick mroderick left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Upgrade Review: ruby-deps group, 7 gems

Verdict: safe to merge. High confidence. All CI checks green (6 test groups, RuboCop, Security Audit, coverage).

PR Scope

Dependency-only. Gemfile.lock gets 13 version bumps plus one Gemfile constraint widening (prawn-svg ~> 0.35 → ~> 0.40). No application code changed. Dependabot listed 7 direct gems; the lockfile diff also carried transitive bumps (css_parser, mime-types-data, playwright-ruby-client, ssrf_filter).

Changes in the Dependencies

All 7 updates are patch/bugfix releases; none documents a breaking change. Notable behavior change: icalendar 2.12.5 removes TZID from DATE values and caps ics parse depth — planner only writes ics files, so unaffected.

Usage in Repository

Gem Call sites Where used Impact of this bump
image_processing 0 Never called directly; Active Storage attachments unused. Kept in Gemfile only as backend-stack insurance for CarrierWave::MiniMagick (see Gemfile comment) #convert extensionless-path change is never triggered. Unused in practice
icalendar 4 3 mailers via WorkshopCalendar / Services::EventCalendar, writing .ics email attachments Planner never parses external ics, and emits DateTime-with-tzid, not DATE values. Unaffected
tzinfo-data passive IANA zone data via icalendar + Rails zone lookups Routine data refresh. Unaffected
capybara-playwright-driver test-only test group, all feature specs Fixes Firefox refresh readiness + blank-line text handling — test-infra fixes, not planner code. CI suite green
simplecov test-only Required when COVERAGE=true (spec_helper) Windows/JRuby + static-extractor fixes; planner does not use that extractor. Unaffected
scout_apm 1 Production APM, configured by env, no initializer 6.3.1 only adds Grape 4 route capture — planner has no Grape. Unused code path
prawn-svg 1 CheckInPdf (check-in sheet PDFs) via Prawn::SVG::Extension initializer Only bump where planner actively runs changed code: 0.40.4 fixes a rendering regression 0.40.3 introduced. Covered by spec/services/check_in_pdf_spec.rb

Dependency weight: the strongest coupling in this batch is prawn-svg in CheckInPdf — exactly where the one real behavior fix lands. icalendar is the next most used (write-only .ics generation in mailers). The rest are test-only, passive data, or never invoked.

Compatibility Assessment

Compatible across all seven. Nothing planner calls changed its contract.

Test Coverage

The paths planner exercises are covered: spec/serializers/workshop_calendar_spec.rb (icalendar writes), spec/services/check_in_pdf_spec.rb (prawn-svg), and the full parallel test suite over the capybara-playwright bump passed on CI.

Confidence Rating

High. Narrow diffs, bugfix-level updates, green CI, and the prawn-svg constraint widening already reflects the 0.40.x line the lockfile has been running since 0.40.3.

@mroderick
mroderick merged commit f57d822 into master Oct 8, 2026
11 checks passed
@mroderick
mroderick deleted the dependabot/bundler/ruby-deps-95bdeb6933 branch October 8, 2026 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant