Skip to content

Bump the ruby-dependencies group with 7 updates - #2149

Merged
edmorley merged 1 commit into
mainfrom
dependabot/bundler/ruby-dependencies-45344973a3
Oct 1, 2026
Merged

edmorley merged 1 commit into
mainfrom
dependabot/bundler/ruby-dependencies-45344973a3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the ruby-dependencies group with 7 updates:

Package From To
rubocop 1.90.0 1.91.0
excon 1.7.1 1.7.2
json 2.21.2 3.0.2
parallel 2.1.0 2.2.0
regexp_parser 2.12.0 2.13.1
unicode-display_width 3.2.0 3.3.0
unicode-emoji 4.2.0 4.3.0

Updates rubocop from 1.90.0 to 1.91.0

Release notes

Sourced from rubocop's releases.

RuboCop v1.91.0

New features

  • #15631: Add a preview channel for unstable behavior. ([@​bbatsov][])
  • #15627: Add a SARIF formatter. ([@​bbatsov][])
  • #15686: Add AllCops: FailLevel, the configuration equivalent of --fail-level. ([@​bbatsov][])
  • #15650: Add AllowedDirectives option to Style/DisableCopsWithinSourceCodeDirective, exempting directive kinds such as generated rubocop:todo comments. ([@​bbatsov][])
  • #15629: Add --changed to inspect only the files git says changed. ([@​bbatsov][])
  • #15628: Add --diff to preview autocorrection without writing files. ([@​bbatsov][])
  • #15615: Add new Lint/MisplacedMagicComment cop to flag magic comments in positions where Ruby ignores them. ([@​bbatsov][])
  • #15600: Add the rubocop:enable-next directive to re-enable cops for the next statement only. ([@​bbatsov][])
  • #15600: Add the rubocop:next directive, combining push-style +/- arguments with disable-next's statement scope. ([@​bbatsov][])
  • #15363: Let a cop's entry in the default configuration carry a Preview section with the defaults it is expected to adopt in the next major release, applied under Preview. ([@​bbatsov][])

Bug fixes

  • #15349: Fix a false positive for Style/RedundantRegexpCharacterClass with \8/\9. ([@​bbatsov][])
  • #15646: Fix an error for Layout/ElseAlignment when else is used with rescue in a class, module, or singleton class body. ([@​viralpraxis][])
  • #15613: Fix an error for Layout/HashAlignment when a hash value starts on the line below its key. ([@​viralpraxis][])
  • #15623: Fix an error for Layout/HashAlignment when the first pair of a hash omits its value, and an incorrect autocorrection when a later pair does. ([@​viralpraxis][])
  • #15602: Fix an error for Layout/IndentationWidth on under-indented code with tab indentation. ([@​Starlexxx][])
  • #15672: Fix an error for Lint/RedundantCopDisableDirective when a file contains more than one rubocop:push/rubocop:pop pair. ([@​koic][])
  • #15625: Fix an error for Style/AccessModifierDeclarations when a body repeats the same access modifier. ([@​viralpraxis][])
  • #15603: Fix an error for Style/AccessModifierDeclarations with EnforcedStyle: inline when an access modifier is the body of an if without an else branch. ([@​viralpraxis][])
  • #15604: Fix an error for Style/ConstantVisibility when a visibility declaration splats anything other than an array literal, e.g. private_constant(*constants(false)). ([@​viralpraxis][])
  • #15647: Fix an error for Style/DocumentationMethod when an inline module_function/ruby2_keywords def is preceded by another argument. ([@​viralpraxis][])
  • #15680: Fix an error for Style/EndlessMethod when a method definition is nested inside another method definition. ([@​viralpraxis][])
  • #15674: Fix an error for Style/FloatDivision when using EnforcedStyle: fdiv and one operand of a float division is itself a parenthesized float division. ([@​viralpraxis][])
  • #15624: Fix an error for Style/HashLookupMethod when the looked-up key is itself a hash lookup. ([@​viralpraxis][])
  • #15642: Fix an error for Style/HashSyntax when hash rockets are enforced and a hash value repeats its key. ([@​viralpraxis][])
  • #15634: Fix an incorrect autocorrect for Lint/LiteralAsCondition when the other operand is a parenthesized return. ([@​Starlexxx][])
  • #15648: Fix an incorrect autocorrect for Lint/ParenthesesAsGroupedExpression when the parentheses contain and, or, not, or a modifier expression. ([@​Starlexxx][])
  • #15612: Fix an incorrect autocorrect for Naming/BlockForwarding with Style/MethodDefParentheses. ([@​Starlexxx][])
  • #15680: Fix an incorrect autocorrect for Style/EndlessMethod when using EnforcedStyle: require_always and the method body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15669: Fix an incorrect autocorrect for Style/FloatDivision when using EnforcedStyle: fdiv and the divisor is a method call with parenthesized arguments. ([@​viralpraxis][])
  • #15678: Fix an incorrect autocorrect for Style/For when using EnforcedStyle: for and the block body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15645: Fix an incorrect autocorrect for Style/GuardClause with Style/MissingElse. ([@​Starlexxx][])
  • #15668: Fix an incorrect autocorrect for Style/MethodCallWithArgsParentheses when EnforcedStyle: omit_parentheses is used together with Style/TrailingCommaInArguments. ([@​viralpraxis][])
  • #15347: Fix an incorrect autocorrect for Style/NestedModifier. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/NonNilCheck. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/Not with a flip-flop or assignment. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantDoubleSplatHashBraces with a braced merge argument. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantParentheses around and/or. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantRegexpConstructor with %r{} delimiters. ([@​bbatsov][])
  • #15614: Fix an infinite loop between Layout/ArgumentAlignment and Layout/HashAlignment with separator style. ([@​Starlexxx][])
  • #15599: Fix an infinite loop error for Layout/CommentIndentation when many comment blocks with the same indentation are separated by empty lines. ([@​Starlexxx][])
  • #15597: Fix an infinite loop error for Layout/EmptyLinesAfterModuleInclusion when a module inclusion is directly before rescue. ([@​Starlexxx][])
  • #15617: Fix an infinite loop between Layout/ExtraSpacing with ForceEqualSignAlignment and Layout/SpaceAroundOperators. ([@​Starlexxx][])
  • #15638: Fix an infinite loop error for Layout/FirstArrayElementIndentation with Layout/ArrayAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])
  • #15639: Fix an infinite loop error for Layout/FirstParameterIndentation with Layout/ParameterAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])

... (truncated)

Changelog

Sourced from rubocop's changelog.

1.91.0 (2026-09-10)

New features

  • #15631: Add a preview channel for unstable behavior. ([@​bbatsov][])
  • #15627: Add a SARIF formatter. ([@​bbatsov][])
  • #15686: Add AllCops: FailLevel, the configuration equivalent of --fail-level. ([@​bbatsov][])
  • #15650: Add AllowedDirectives option to Style/DisableCopsWithinSourceCodeDirective, exempting directive kinds such as generated rubocop:todo comments. ([@​bbatsov][])
  • #15629: Add --changed to inspect only the files git says changed. ([@​bbatsov][])
  • #15628: Add --diff to preview autocorrection without writing files. ([@​bbatsov][])
  • #15615: Add new Lint/MisplacedMagicComment cop to flag magic comments in positions where Ruby ignores them. ([@​bbatsov][])
  • #15600: Add the rubocop:enable-next directive to re-enable cops for the next statement only. ([@​bbatsov][])
  • #15600: Add the rubocop:next directive, combining push-style +/- arguments with disable-next's statement scope. ([@​bbatsov][])
  • #15363: Let a cop's entry in the default configuration carry a Preview section with the defaults it is expected to adopt in the next major release, applied under Preview. ([@​bbatsov][])

Bug fixes

  • #15349: Fix a false positive for Style/RedundantRegexpCharacterClass with \8/\9. ([@​bbatsov][])
  • #15646: Fix an error for Layout/ElseAlignment when else is used with rescue in a class, module, or singleton class body. ([@​viralpraxis][])
  • #15613: Fix an error for Layout/HashAlignment when a hash value starts on the line below its key. ([@​viralpraxis][])
  • #15623: Fix an error for Layout/HashAlignment when the first pair of a hash omits its value, and an incorrect autocorrection when a later pair does. ([@​viralpraxis][])
  • #15602: Fix an error for Layout/IndentationWidth on under-indented code with tab indentation. ([@​Starlexxx][])
  • #15672: Fix an error for Lint/RedundantCopDisableDirective when a file contains more than one rubocop:push/rubocop:pop pair. ([@​koic][])
  • #15625: Fix an error for Style/AccessModifierDeclarations when a body repeats the same access modifier. ([@​viralpraxis][])
  • #15603: Fix an error for Style/AccessModifierDeclarations with EnforcedStyle: inline when an access modifier is the body of an if without an else branch. ([@​viralpraxis][])
  • #15604: Fix an error for Style/ConstantVisibility when a visibility declaration splats anything other than an array literal, e.g. private_constant(*constants(false)). ([@​viralpraxis][])
  • #15647: Fix an error for Style/DocumentationMethod when an inline module_function/ruby2_keywords def is preceded by another argument. ([@​viralpraxis][])
  • #15680: Fix an error for Style/EndlessMethod when a method definition is nested inside another method definition. ([@​viralpraxis][])
  • #15674: Fix an error for Style/FloatDivision when using EnforcedStyle: fdiv and one operand of a float division is itself a parenthesized float division. ([@​viralpraxis][])
  • #15624: Fix an error for Style/HashLookupMethod when the looked-up key is itself a hash lookup. ([@​viralpraxis][])
  • #15642: Fix an error for Style/HashSyntax when hash rockets are enforced and a hash value repeats its key. ([@​viralpraxis][])
  • #15634: Fix an incorrect autocorrect for Lint/LiteralAsCondition when the other operand is a parenthesized return. ([@​Starlexxx][])
  • #15648: Fix an incorrect autocorrect for Lint/ParenthesesAsGroupedExpression when the parentheses contain and, or, not, or a modifier expression. ([@​Starlexxx][])
  • #15612: Fix an incorrect autocorrect for Naming/BlockForwarding with Style/MethodDefParentheses. ([@​Starlexxx][])
  • #15680: Fix an incorrect autocorrect for Style/EndlessMethod when using EnforcedStyle: require_always and the method body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15669: Fix an incorrect autocorrect for Style/FloatDivision when using EnforcedStyle: fdiv and the divisor is a method call with parenthesized arguments. ([@​viralpraxis][])
  • #15678: Fix an incorrect autocorrect for Style/For when using EnforcedStyle: for and the block body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15645: Fix an incorrect autocorrect for Style/GuardClause with Style/MissingElse. ([@​Starlexxx][])
  • #15668: Fix an incorrect autocorrect for Style/MethodCallWithArgsParentheses when EnforcedStyle: omit_parentheses is used together with Style/TrailingCommaInArguments. ([@​viralpraxis][])
  • #15347: Fix an incorrect autocorrect for Style/NestedModifier. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/NonNilCheck. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/Not with a flip-flop or assignment. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantDoubleSplatHashBraces with a braced merge argument. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantParentheses around and/or. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantRegexpConstructor with %r{} delimiters. ([@​bbatsov][])
  • #15614: Fix an infinite loop between Layout/ArgumentAlignment and Layout/HashAlignment with separator style. ([@​Starlexxx][])
  • #15599: Fix an infinite loop error for Layout/CommentIndentation when many comment blocks with the same indentation are separated by empty lines. ([@​Starlexxx][])
  • #15597: Fix an infinite loop error for Layout/EmptyLinesAfterModuleInclusion when a module inclusion is directly before rescue. ([@​Starlexxx][])
  • #15617: Fix an infinite loop between Layout/ExtraSpacing with ForceEqualSignAlignment and Layout/SpaceAroundOperators. ([@​Starlexxx][])
  • #15638: Fix an infinite loop error for Layout/FirstArrayElementIndentation with Layout/ArrayAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])

... (truncated)

Commits
  • 6eee0af Cut 1.91
  • ed0572d Update Changelog
  • 3181272 Fix an infinite loop for Style/NumericLiteralPrefix with signed literals
  • b87652a Fix Layout/LineLength SplitStrings loop on trailing-space split point
  • fce7a33 [Fix #15638] Fix first array indentation loop
  • 321bd65 #15347 Fix an incorrect autocorrect for Style/NestedModifier
  • a464cba #15347 Fix incorrect autocorrects for Style/NilComparison with precedence...
  • 3192b70 #15347 Fix an incorrect autocorrect for Style/NonNilCheck
  • f747cab #15347 Fix an incorrect autocorrect for Style/Not with a flip-flop or ass...
  • 3f52020 Add CHANGELOG entry for the preview fail level
  • Additional commits viewable in compare view

Updates excon from 1.7.1 to 1.7.2

Changelog

Sourced from excon's changelog.

1.7.2 2026-09-28

  • updated bundled certs
Commits

Updates json from 2.21.2 to 3.0.2

Release notes

Sourced from json's releases.

v3.0.0

With the removal of the insecure create_additions option, JSON.load and JSON.dump are now safe to use. Them being unsafe by default caused multiple security vulnerabilites in the past.

If you did depend on create_additions, the recommended migration is to implement a custom serializer using JSON::Coder.

All the mutable default options, such as JSON.load_default_options have been removed. They were preventing Ractor compatiblity, and causing bug in libraries using JSON expecting the default behavior. JSON methods now always behave the same unless monkey patched.

All methods options are now either keyword arguments or checked like keyword arguments, meaning unknown options such as typos raise ArgumentError.

Duplicated keys are now rejected by default.

JavaScript comments in documents are no longer supported by default.

Numerous rarely used aliases have been removed.

  • Add JSON::ParserError#json_path to locate parse errors in the document as a JSONPath-style string (e.g. $.foo[0].bar). For duplicate key errors it points at the duplicated key itself.
  • Fix the parser to also reject lone trailing UTF-16 surrogates (\uDCxx with no leading partner), symmetric to the leading-surrogate case. The Java parser already rejected these; this closes the CRuby/JRuby parity gap.
  • JSON.load defaults are now safe to use.
  • All unknown options will now cause an ArgumentError rather than to be ignored.
  • The allow_comments parsing option now defaults to false.
  • The allow_duplicate_key option now defaults to false, for both parsing and generating JSON.
  • Removed the limit positional argument of JSON.dump.
  • Removed the escape_slash alias of script_safe.
  • Removed Kernel#j and Kernel#jj.
  • Removed JSON.load_default_options.
  • Removed JSON.unsafe_load_default_options.
  • Removed JSON.dump_default_options.
  • Removed JSON::State#[] and JSON::State#[]=.
  • Removed JSON.unparse.
  • Removed JSON.fast_generate.
  • Removed JSON.fast_unparse.
  • Removed JSON.pretty_unparse.
  • Removed JSON.restore.
  • Removed JSON::PRETTY_STATE_PROTOTYPE.
  • Removed the insecure create_additions option.
  • Removed JSON::GenericObject.

Full Changelog: ruby/json@v2.21.2...v3.0.0

v3.0.0.rc1

With the removal of the insecure create_additions option, JSON.load and JSON.dump are now safe to use. Them being unsafe by default caused multiple security vulnerabilites in the past.

If you did depend on create_additions, the recommended migration is to implement a custom serializer using JSON::Coder.

All the mutable default options, such as JSON.load_default_options have been removed. They were preventing Ractor compatiblity, and causing bug in libraries using JSON expecting the default behavior. JSON methods now always behave the same unless monkey patched.

... (truncated)

Changelog

Sourced from json's changelog.

2026-09-09 (3.0.2)

  • Fix JSON.load_file and JSON.load_file! to load on Ruby 2.7.0 through 2.7.2, which cannot parse a leading parameter before ....

2026-09-08 (3.0.1)

  • Restore the limit positional argument of JSON.dump.

2026-09-07 (3.0.0)

  • Add JSON::ParserError#json_path to locate parse errors in the document as a JSONPath-style string (e.g. $.foo[0].bar). For duplicate key errors it points at the duplicated key itself.
  • Fix the parser to also reject lone trailing UTF-16 surrogates (\uDCxx with no leading partner), symmetric to the leading-surrogate case. The Java parser already rejected these; this closes the CRuby/JRuby parity gap.

2026-08-11 (3.0.0.rc1)

With the removal of the insecure create_additions option, JSON.load and JSON.dump are now safe to use. Them being unsafe by default caused multiple security vulnerabilites in the past.

If you did depend on create_additions, the recommended migration is to implement a custom serializer using JSON::Coder.

All the mutable default options, such as JSON.load_default_options have been removed. They were preventing Ractor compatiblity, and causing bug in libraries using JSON expecting the default behavior. JSON methods now always behave the same unless monkey patched.

All methods options are now either keyword arguments or checked like keyword arguments, meaning unknown options such as typos raise ArgumentError.

Duplicated keys are now rejected by default.

JavaScript comments in documents are no longer supported by default.

Numerous rarely used aliases have been removed.

  • JSON.load defaults are now safe to use.
  • All unknown options will now cause an ArgumentError rather than to be ignored.
  • The allow_comments parsing option now defaults to false.
  • The allow_duplicate_key option now defaults to false, for both parsing and generating JSON.
  • Removed the limit positional argument of JSON.dump.
  • Removed the escape_slash alias of script_safe.
  • Removed Kernel#j and Kernel#jj.
  • Removed JSON.load_default_options.
  • Removed JSON.unsafe_load_default_options.
  • Removed JSON.dump_default_options.
  • Removed JSON::State#[] and JSON::State#[]=.
  • Removed JSON.unparse.
  • Removed JSON.fast_generate.
  • Removed JSON.fast_unparse.
  • Removed JSON.pretty_unparse.
  • Removed JSON.restore.

... (truncated)

Commits
  • 7b2a23d Release 3.0.2
  • effca27 Fix the JSON::Coder.new call-seq
  • 8bdd517 Update documentation to match json 3.0 API
  • 29dad14 Fix JSON.load_file and JSON.load_file! to load on Ruby 2.7.0 through 2.7.2
  • 73edd53 Centralize requires in the test suite
  • c557a62 Release 3.0.1
  • 566bd7c Restore the limit positional argument of JSON.dump
  • 9427d36 Release 3.0.0
  • 82bf6be Fix parser silently accepting a lone trailing surrogate in string values
  • 1d37403 Stop installing ragel on CI
  • Additional commits viewable in compare view

Updates parallel from 2.1.0 to 2.2.0

Changelog

Sourced from parallel's changelog.

2.2.0

Added

  • Redact HMAC secrets from inspect output

Fixed

  • filter_map rejects falsy valus
  • restore the outer worker number after direct execution
  • compare producer stop markers by identity
  • ractor stop and crash handling
  • ractor direct mode with 0 workers
  • avoid storing or transferring discarded each results
  • ractor item index works
  • validate worker counts
  • clean up partially created process workers
  • avoid storing or transferring discarded each results
Commits
  • 582ae13 v2.2.0
  • fd824df Merge pull request #390 from OskarEichler/codex/security-redact-hmac-secret
  • 1b1bd98 Merge pull request #392 from grosser/grosser/read
  • c4eeeec pin permissions to read
  • 574da0f Redact HMAC secrets from inspect output
  • c032f43 Merge pull request #385 from OskarEichler/codex/validate-worker-counts
  • 0720b14 Merge pull request #389 from grosser/OskarEichler-codex/cleanup-ractors-on-pa...
  • b7c01eb tests
  • 6f51a55 cleanup
  • 2622bee Stop Ractors after parent-side failures
  • Additional commits viewable in compare view

Updates regexp_parser from 2.12.0 to 2.13.1

Changelog

Sourced from regexp_parser's changelog.

[2.13.1] - 2026-09-28 - Janosch Müller

Fixed

  • support lone \p expressions and scan them as escaped literal (#111)
    • match Ruby's behavior, which only warns for \p without a curly bracket
    • thanks to Jason Barnabe for the report

[2.13.0] - 2026-09-21 - Janosch Müller

Added

  • greatly improved scanning, lexing, and parsing performance
    • ~5x for a single-expression patterns, ~2x for a 500-expression pattern
  • improved performance of #each_expression and #traverse
  • greatly improved performance when comparing parse results (via #==)
  • improved scanner error messages for invalid patterns, e.g. '\xZ'

Fixed

  • SystemStackError when parsing or traversing very deeply nested trees (#109)
  • minor memory leak when accepting arbitrary user input as syntax version (#109)
  • #match_length now respects the quantifier of backrefs and subexp calls (#107)
  • #match_length now handles backref/subexp call multiplexing (#107)
  • thanks to Oskar Eichler for reporting these
Commits
  • c0f4098 Release v2.13.1
  • 5e4ba3b Handle lone \p, fixes #111
  • a706d28 Release v2.13.0
  • 9364abd Update year [ci skip]
  • 495b2c4 Merge pull request #110 from ammar/improve-performance-and-memory-use
  • 6aa5f4d Improve performance and prevent SystemStackError
  • 4fedf0c Remove redundant gemspec metadata ...
  • 13c9b53 Remove unnecessary load path pollution
  • 9396d6a Omit platform from gemspec ...
  • ed1db74 Omit Gemfile, Rakefile, rl files from bundled gem
  • Additional commits viewable in compare view

Updates unicode-display_width from 3.2.0 to 3.3.0

Changelog

Sourced from unicode-display_width's changelog.

3.3.0

  • Unicode 18.0
  • Fix bug that emoji handling could not be deactivated when using config object
  • Fix edge case to not modify string when failing parsing binary input as UTF-8
Commits
  • 7aa2280 Release v3.3.0
  • 552e624 Upgrade Emoji library to 18.0, too
  • 5f3d9bf Add CHANGELOG entry
  • 534b4b5 Update Unicode version number
  • 8a9f247 Unicode 18.0
  • 42d1297 Update license year
  • 8fafc50 Merge pull request #38 from OskarEichler/codex/security-pin-ci-actions
  • 53d0c18 Merge pull request #36 from OskarEichler/codex/preserve-binary-input
  • 7731a91 Merge pull request #34 from OskarEichler/codex/allow-false-emoji-override
  • afe98ea Merge pull request #33 from OskarEichler/codex/fix-ci-rgi-mode
  • Additional commits viewable in compare view

Updates unicode-emoji from 4.2.0 to 4.3.0

Changelog

Sourced from unicode-emoji's changelog.

4.3.0

  • Unicode / Emoji 18.0
Commits
  • db9d94d Release v4.3.0
  • 4ececcc Regenerate Emoji regexes for Unicode 18.0
  • 49b3769 Update Unicode version numbers to 18.0
  • 978b151 Unicode 18.0
  • b7ad287 Update license year
  • 781d792 Update CI Rubies: Remove Ruby 3.1
  • aeb6e18 Update CI Rubies: Remove Ruby 3.0
  • 71932f1 README: Update CLDR version
  • 0ad1de0 Merge pull request #26 from OskarEichler/codex/security-pin-ci-actions
  • 0db774a Merge pull request #21 from OskarEichler/codex/freeze-subdivision-data
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the ruby-dependencies group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [rubocop](https://github.com/rubocop/rubocop) | `1.90.0` | `1.91.0` |
| [excon](https://github.com/excon/excon) | `1.7.1` | `1.7.2` |
| [json](https://github.com/ruby/json) | `2.21.2` | `3.0.2` |
| [parallel](https://github.com/grosser/parallel) | `2.1.0` | `2.2.0` |
| [regexp_parser](https://github.com/ammar/regexp_parser) | `2.12.0` | `2.13.1` |
| [unicode-display_width](https://github.com/janlelis/unicode-display_width) | `3.2.0` | `3.3.0` |
| [unicode-emoji](https://github.com/janlelis/unicode-emoji) | `4.2.0` | `4.3.0` |


Updates `rubocop` from 1.90.0 to 1.91.0
- [Release notes](https://github.com/rubocop/rubocop/releases)
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop@v1.90.0...v1.91.0)

Updates `excon` from 1.7.1 to 1.7.2
- [Changelog](https://github.com/excon/excon/blob/master/changelog.txt)
- [Commits](excon/excon@v1.7.1...v1.7.2)

Updates `json` from 2.21.2 to 3.0.2
- [Release notes](https://github.com/ruby/json/releases)
- [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md)
- [Commits](ruby/json@v2.21.2...v3.0.2)

Updates `parallel` from 2.1.0 to 2.2.0
- [Changelog](https://github.com/grosser/parallel/blob/master/CHANGELOG.md)
- [Commits](grosser/parallel@v2.1.0...v2.2.0)

Updates `regexp_parser` from 2.12.0 to 2.13.1
- [Changelog](https://github.com/ammar/regexp_parser/blob/master/CHANGELOG.md)
- [Commits](ammar/regexp_parser@v2.12.0...v2.13.1)

Updates `unicode-display_width` from 3.2.0 to 3.3.0
- [Changelog](https://github.com/janlelis/unicode-display_width/blob/main/CHANGELOG.md)
- [Commits](janlelis/unicode-display_width@v3.2.0...v3.3.0)

Updates `unicode-emoji` from 4.2.0 to 4.3.0
- [Changelog](https://github.com/janlelis/unicode-emoji/blob/main/CHANGELOG.md)
- [Commits](janlelis/unicode-emoji@v4.2.0...v4.3.0)

---
updated-dependencies:
- dependency-name: rubocop
  dependency-version: 1.91.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
- dependency-name: excon
  dependency-version: 1.7.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: ruby-dependencies
- dependency-name: json
  dependency-version: 3.0.2
  dependency-type: indirect
  update-type: version-update:semver-major
  dependency-group: ruby-dependencies
- dependency-name: parallel
  dependency-version: 2.2.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
- dependency-name: regexp_parser
  dependency-version: 2.13.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
- dependency-name: unicode-display_width
  dependency-version: 3.3.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
- dependency-name: unicode-emoji
  dependency-version: 4.3.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: ruby-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
@dependabot
dependabot Bot requested a review from edmorley as a code owner October 1, 2026 14:53
@dependabot dependabot Bot added ruby Dependabot pull requests that update Ruby dependencies skip changelog dependencies Pull requests that update a dependency file labels Oct 1, 2026
@edmorley
edmorley merged commit 0d8fd7a into main Oct 1, 2026
14 of 15 checks passed
@edmorley
edmorley deleted the dependabot/bundler/ruby-dependencies-45344973a3 branch October 1, 2026 20:36
@heroku-linguist heroku-linguist Bot mentioned this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Dependabot pull requests that update Ruby dependencies skip changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant