Skip to content

Bump rails from 8.0.5.1 to 8.1.3.1 - #101

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/rails-8.1.1
Closed

Bump rails from 8.0.5.1 to 8.1.3.1#101
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/rails-8.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 29, 2025

Copy link
Copy Markdown
Contributor

Bumps rails from 8.0.5.1 to 8.1.3.1.

Release notes

Sourced from rails's releases.

8.1.3.1

Active Support

  • No changes.

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • No changes.

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Disable libvips's unfuzzed image loaders and savers.

    libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only safe for trusted content. Active Storage will call Vips.block_untrusted(true) to disable them while booting. An application that needs a specific loader or saver may re-enable it in an initializer.

... (truncated)

Commits
  • 3989ebf Preparing for 8.1.3.1 release
  • 349e7a5 Disable libvips's unfuzzed image loaders and savers
  • fa8f081 Preparing for 8.1.3 release
  • 63cef3d Merge branch '8-1-sec' into 8-1-stable
  • 1db4b89 Preparing for 8.1.2.1 release
  • 1c7d1cf Update changelog
  • e91694b Update CHANGELOG (8.1 only)
  • 6752711 Fix XSS in debug exceptions copy-to-clipboard
  • 63f5ad8 Skip blank attribute names in Action View tag helpers
  • 8c9676b Prevent glob injection in ActiveStorage DiskService#delete_prefixed
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Oct 29, 2025
@dependabot
dependabot Bot force-pushed the dependabot/bundler/rails-8.1.1 branch from 6b4db6d to 00d35d5 Compare October 29, 2025 19:14
@dependabot
dependabot Bot force-pushed the dependabot/bundler/rails-8.1.1 branch from 00d35d5 to 03a991a Compare November 10, 2025 18:25
@dependabot
dependabot Bot force-pushed the dependabot/bundler/rails-8.1.1 branch from 03a991a to dfcca7f Compare November 20, 2025 16:33
@dependabot
dependabot Bot force-pushed the dependabot/bundler/rails-8.1.1 branch 2 times, most recently from a304600 to 2e9f8f7 Compare November 27, 2025 17:41
@3kh0

3kh0 commented Sep 3, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot changed the title Bump rails from 8.0.3 to 8.1.1 Bump rails from 8.0.5.1 to 8.1.3.1 Sep 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/bundler/rails-8.1.1 branch from 2e9f8f7 to 29da5d0 Compare September 3, 2026 13:38
@socket-security

socket-security Bot commented Sep 3, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedrails@​8.0.5.1 ⏵ 8.1.3.110010090100100

View full report

@socket-security

socket-security Bot commented Sep 3, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: gem actionpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: Gemfile.lockgem/ferrum_pdf@3.1.0gem/importmap-rails@2.2.3gem/turbo-rails@2.0.23gem/web-console@4.3.0gem/propshaft@1.3.2gem/tailwindcss-rails@4.6.0gem/solid_cable@4.0.2gem/rails@8.1.3.1gem/blazer@3.5.1gem/solid_queue@1.7.0gem/mission_control-jobs@1.2.0gem/sentry-rails@7.0.0gem/active_storage_validations@4.1.1gem/stimulus-rails@1.3.4gem/hotwire-livereload@2.1.1gem/solid_cache@1.0.10gem/dotenv-rails@3.2.0gem/actionpack@8.1.3.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore gem/actionpack@8.1.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: gem activerecord is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: Gemfile.lockgem/flipper-active_record@1.4.2gem/solid_cable@4.0.2gem/annotaterb@4.24.0gem/rails@8.1.3.1gem/blazer@3.5.1gem/solid_queue@1.7.0gem/mission_control-jobs@1.2.0gem/active_storage_validations@4.1.1gem/paper_trail@17.0.0gem/solid_cache@1.0.10gem/activerecord@8.1.3.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore gem/activerecord@8.1.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: gem activerecord is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: Gemfile.lockgem/flipper-active_record@1.4.2gem/solid_cable@4.0.2gem/annotaterb@4.24.0gem/rails@8.1.3.1gem/blazer@3.5.1gem/solid_queue@1.7.0gem/mission_control-jobs@1.2.0gem/active_storage_validations@4.1.1gem/paper_trail@17.0.0gem/solid_cache@1.0.10gem/activerecord@8.1.3.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore gem/activerecord@8.1.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@3kh0

3kh0 commented Sep 3, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [rails](https://github.com/rails/rails) from 8.0.5.1 to 8.1.3.1.
- [Release notes](https://github.com/rails/rails/releases)
- [Commits](rails/rails@v8.0.5.1...v8.1.3.1)

---
updated-dependencies:
- dependency-name: rails
  dependency-version: 8.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/rails-8.1.1 branch from 29da5d0 to 849f7e3 Compare September 3, 2026 14:56
@3kh0

3kh0 commented Sep 3, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

Looks like rails is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 3, 2026
@dependabot
dependabot Bot deleted the dependabot/bundler/rails-8.1.1 branch September 3, 2026 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant