Repository navigation
chore(deps): bump the ruby-deps group with 7 updates - #2995
Conversation
Bumps the ruby-deps group with 7 updates: | Package | From | To | | --- | --- | --- | | [image_processing](https://github.com/janko/image_processing) | `2.1.0` | `2.2.0` | | [icalendar](https://github.com/icalendar/icalendar) | `2.12.4` | `2.12.5` | | [tzinfo-data](https://github.com/tzinfo/tzinfo-data) | `1.2026.4` | `1.2026.5` | | [capybara-playwright-driver](https://github.com/YusukeIwaki/capybara-playwright-driver) | `0.5.10` | `0.5.12` | | [simplecov](https://github.com/simplecov-ruby/simplecov) | `1.3.0` | `1.3.2` | | [scout_apm](https://github.com/scoutapp/scout_apm_ruby) | `6.3.0` | `6.3.1` | | [prawn-svg](https://github.com/mogest/prawn-svg) | `0.40.3` | `0.40.4` | Updates `image_processing` from 2.1.0 to 2.2.0 - [Changelog](https://github.com/janko/image_processing/blob/master/CHANGELOG.md) - [Commits](janko/image_processing@v2.1.0...v2.2.0) Updates `icalendar` from 2.12.4 to 2.12.5 - [Changelog](https://github.com/icalendar/icalendar/blob/main/CHANGELOG.md) - [Commits](icalendar/icalendar@v2.12.4...v2.12.5) Updates `tzinfo-data` from 1.2026.4 to 1.2026.5 - [Release notes](https://github.com/tzinfo/tzinfo-data/releases) - [Commits](tzinfo/tzinfo-data@v1.2026.4...v1.2026.5) Updates `capybara-playwright-driver` from 0.5.10 to 0.5.12 - [Commits](YusukeIwaki/capybara-playwright-driver@0.5.10...0.5.12) Updates `simplecov` from 1.3.0 to 1.3.2 - [Release notes](https://github.com/simplecov-ruby/simplecov/releases) - [Changelog](https://github.com/simplecov-ruby/simplecov/blob/main/CHANGELOG.md) - [Commits](simplecov-ruby/simplecov@v1.3.0...v1.3.2) Updates `scout_apm` from 6.3.0 to 6.3.1 - [Changelog](https://github.com/scoutapp/scout_apm_ruby/blob/master/CHANGELOG.markdown) - [Commits](scoutapp/scout_apm_ruby@v6.3.0...v6.3.1) Updates `prawn-svg` from 0.40.3 to 0.40.4 - [Release notes](https://github.com/mogest/prawn-svg/releases) - [Commits](mogest/prawn-svg@v0.40.3...v0.40.4) --- updated-dependencies: - dependency-name: image_processing dependency-version: 2.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ruby-deps - dependency-name: icalendar dependency-version: 2.12.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-deps - dependency-name: tzinfo-data dependency-version: 1.2026.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-deps - dependency-name: capybara-playwright-driver dependency-version: 0.5.12 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: ruby-deps - dependency-name: simplecov dependency-version: 1.3.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: ruby-deps - dependency-name: scout_apm dependency-version: 6.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-deps - dependency-name: prawn-svg dependency-version: 0.40.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ruby-deps ... Signed-off-by: dependabot[bot] <support@github.com>
mroderick
left a comment
There was a problem hiding this comment.
Dependency Upgrade Review: ruby-deps group, 7 gems
Verdict: safe to merge. High confidence. All CI checks green (6 test groups, RuboCop, Security Audit, coverage).
PR Scope
Dependency-only. Gemfile.lock gets 13 version bumps plus one Gemfile constraint widening (prawn-svg ~> 0.35 → ~> 0.40). No application code changed. Dependabot listed 7 direct gems; the lockfile diff also carried transitive bumps (css_parser, mime-types-data, playwright-ruby-client, ssrf_filter).
Changes in the Dependencies
All 7 updates are patch/bugfix releases; none documents a breaking change. Notable behavior change: icalendar 2.12.5 removes TZID from DATE values and caps ics parse depth — planner only writes ics files, so unaffected.
Usage in Repository
| Gem | Call sites | Where used | Impact of this bump |
|---|---|---|---|
| image_processing | 0 | Never called directly; Active Storage attachments unused. Kept in Gemfile only as backend-stack insurance for CarrierWave::MiniMagick (see Gemfile comment) | #convert extensionless-path change is never triggered. Unused in practice |
| icalendar | 4 | 3 mailers via WorkshopCalendar / Services::EventCalendar, writing .ics email attachments |
Planner never parses external ics, and emits DateTime-with-tzid, not DATE values. Unaffected |
| tzinfo-data | passive | IANA zone data via icalendar + Rails zone lookups | Routine data refresh. Unaffected |
| capybara-playwright-driver | test-only | test group, all feature specs |
Fixes Firefox refresh readiness + blank-line text handling — test-infra fixes, not planner code. CI suite green |
| simplecov | test-only | Required when COVERAGE=true (spec_helper) |
Windows/JRuby + static-extractor fixes; planner does not use that extractor. Unaffected |
| scout_apm | 1 | Production APM, configured by env, no initializer | 6.3.1 only adds Grape 4 route capture — planner has no Grape. Unused code path |
| prawn-svg | 1 | CheckInPdf (check-in sheet PDFs) via Prawn::SVG::Extension initializer |
Only bump where planner actively runs changed code: 0.40.4 fixes a rendering regression 0.40.3 introduced. Covered by spec/services/check_in_pdf_spec.rb |
Dependency weight: the strongest coupling in this batch is prawn-svg in CheckInPdf — exactly where the one real behavior fix lands. icalendar is the next most used (write-only .ics generation in mailers). The rest are test-only, passive data, or never invoked.
Compatibility Assessment
Compatible across all seven. Nothing planner calls changed its contract.
Test Coverage
The paths planner exercises are covered: spec/serializers/workshop_calendar_spec.rb (icalendar writes), spec/services/check_in_pdf_spec.rb (prawn-svg), and the full parallel test suite over the capybara-playwright bump passed on CI.
Confidence Rating
High. Narrow diffs, bugfix-level updates, green CI, and the prawn-svg constraint widening already reflects the 0.40.x line the lockfile has been running since 0.40.3.
Bumps the ruby-deps group with 7 updates:
2.1.02.2.02.12.42.12.51.2026.41.2026.50.5.100.5.121.3.01.3.26.3.06.3.10.40.30.40.4Updates
image_processingfrom 2.1.0 to 2.2.0Changelog
Sourced from image_processing's changelog.
Commits
d9737fbSet version to 2.2.08f7b538Handle missing AVIF encoder in tests92086c5Handle AVIF format on extensionless destinations5827e83Save in the#convertformat to an extensionless destination (#150)Updates
icalendarfrom 2.12.4 to 2.12.5Changelog
Sourced from icalendar's changelog.
Commits
0bcfef3Bump version to 2.12.518803f0Merge pull request #326 from bensynapse/fix-timezone-transition-onsetsfdaafa5Merge pull request #327 from icalendar/limit-parse-depthc7cd145Remove EOL ruby from testing matrix849b39aLimit how deeply nested an ics file can bec68c941Add failing test for parse depthcee52d1Fix generated timezone transition onsetsa085861Merge pull request #325 from henrahmagix/patch-11b6cc48Delete tzid: keyword arg from DATE valuesUpdates
tzinfo-datafrom 1.2026.4 to 1.2026.5Release notes
Sourced from tzinfo-data's releases.
Commits
8df8badUpdate to tzdata version 2026e.Updates
capybara-playwright-driverfrom 0.5.10 to 0.5.12Commits
ff26b750.5.124f933a5Merge pull request #163 from YusukeIwaki/codex/fix-firefox-refresheae2476Wait for initial POST navigation in refresh specscb4eda9Merge pull request #161 from YusukeIwaki/codex/preserve-visible-text-blank-lines9d394e0Remove the dedicated refresh CI job0a23570Identify the reloaded document before checking readiness271f201Address visible text review feedback8dd6e55Wait for Firefox refresh to finish loadinge0252aaPreserve blank lines in visible text7d08ad6Merge pull request #160 from YusukeIwaki/codex/fix-stale-action-retriesUpdates
simplecovfrom 1.3.0 to 1.3.2Release notes
Sourced from simplecov's releases.
Changelog
Sourced from simplecov's changelog.
Commits
52a8754Bump version to 1.3.24fb4ae1Format a result collected before exit on Rails 8.1.41476741bundle update343a933Stop leaking a flush thread in the forked-child production specse64fcaaBump ruby/setup-ruby from 1.323.0 to 1.325.0cb8bd83Bump oxlint from 1.83.0 to 1.85.0 in /html_frontend4ee7894Bump version to 1.3.1486e55ebundle updated2a62a8Resolve paths and wait on runners correctly on JRuby on Windows3a2e08eLoad Prism only when the static extractor runsUpdates
scout_apmfrom 6.3.0 to 6.3.1Changelog
Sourced from scout_apm's changelog.
Commits
03d23eeVersion bump 6.3.1 (#636)f25224cFix flaky HTTPX and Typhoeus instrument tests (#637)e014d7bCapture route names for Grape 4 (#635)Updates
prawn-svgfrom 0.40.3 to 0.40.4Release notes
Sourced from prawn-svg's releases.
Commits
db5455bversion 0.40.4406fdccuse https for rubygems7de74e6Merge pull request #203 from notpeter/fix_chromium_fix25fe93ffix: Chromium fix broke Acrobatffbf01dTreat <a> with empty or missing href as a plain containerDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions