Skip to content

Bump the development-dependencies group across 1 directory with 2 updates - #494

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/development-dependencies-e6d0d339d6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/development-dependencies-e6d0d339d6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 2 updates in the / directory: brakeman and selenium-webdriver.

Updates brakeman from 8.0.6 to 8.1.0

Release notes

Sourced from brakeman's releases.

8.1.0

  • Update SonarQube report to use generic issue format (@​fffx)
  • Include regex code in validation warnings (@​eliotsykes)
  • Check validation regexes in non-activerecord models (@​eliotsykes)
  • Skip top-level vendor directory before recursive globbing (@​ronocod)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (@​cubasepp / @​Eljees)
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (@​Eljees)
  • Fix frozen string error (@​shaicoleman)
  • Better help and error message for --ensure-latest (#2036)
Changelog

Sourced from brakeman's changelog.

8.1.0 - 2026-09-30

  • Better help and error message for --ensure-latest
  • Fix frozen string error (Shai Coleman)
  • Update Sonar report format (fangxing)
  • Fix frozen src string error
  • Recognize Haml::AttributeBuilder.build_class as an escaped output (Yuriy Tumanov)
  • Include regex code in validation warnings (Eliot Sykes)
  • Check validation regexes in non-activerecord models (Eliot Sykes)
  • Skip top-level vendor directory before recursive globbing (Conor O'Donnell)
  • Support Rails 7.1+ positional enum syntax in SQL injection check (Michael Vogl/Yuriy Tumanov)
Commits
  • c778164 Bump to 8.1.0
  • 4621407 Update CHANGES
  • 26ba01f Support Rails 7.1+ positional enum syntax in SQL injection check (#2051)
  • 8f04922 Skip top-level vendor directory before recursive globbing (#2039)
  • f921f01 Check validation regexes in non-activerecord models (#2053)
  • d62e919 Fix CheckValidationRegex overly broad ignores (#2050)
  • 73bbc99 Recognize Haml::AttributeBuilder.build_class as an escaped output (#2052)
  • 71f8f69 Fix typo in test_format_validation_with_multiline (#2049)
  • 0fd4dbc Add bundle install step to contributing doc (#2047)
  • 5de415c Fix ERB frozen src error (#2048)
  • Additional commits viewable in compare view

Updates selenium-webdriver from 4.45.0 to 4.50.0

Release notes

Sourced from selenium-webdriver's releases.

Selenium 4.50.0

Detailed Changelogs by Component

Java     |     Python     |     DotNet     |     Ruby     |     JavaScript

What's Changed

... (truncated)

Changelog

Sourced from selenium-webdriver's changelog.

4.50.0 (2026-09-30)

  • Support CDP versions: v152, v153, v154
  • render WebSocket debug log lines lazily (#18033)
  • Implement driver methods for installing and uninstalling web extensions via BiDi (#17879)
  • [build] Automated CDDL Spec Update (#18046)
  • [build] replace the BiDi KNOWN_INCOMPLETE allowlist with spec-shaped CDDL overlays (#18057)
  • [build] generate the BiDi schema vendor section from Mozilla's Firefox CDDL (#18060)
  • remove deprecated Firefox profile extension and cert methods (#18066)
  • [build] add support for Mozilla's Commands fragment in the BiDi schema (#18071)
  • [build] Automated Browser Version Update (major) with CDP (#18067)
  • [build] Automated CDDL Spec Update (#18075)

4.49.0 (2026-09-09)

  • Support CDP versions: v151, v152, v153
  • derive BiDi field names and enum value types in the schema (#17966)
  • [build] Automated CDDL Spec Update (#17990)
  • [build] ship prebuilt Selenium Manager Linux arm64 binary in all bindings (#17999)
  • [build] Automated Browser Version Update (major) with CDP (#18005)

4.48.0 (2026-08-27)

  • Support CDP versions: v150, v151, v152
  • add low-level BiDi protocol integration specs (#17878)
  • [build] Automated Browser Version Update (major) with CDP (#17910)
  • fix silent hang on oversized WebSocket frames (#17655)
  • always reject a missing required inbound BiDi field (#17936)
  • accept a whole-valued float for an integer BiDi field (#17939)
  • reject an inbound BiDi scalar outside its union's declared arms (#17947)

4.47.0 (2026-08-10)

  • Support CDP versions: v149, v150, v151
  • support WebDriver BiDi on Safari Preview and move #bidi onto Driver (#17729)
  • link generated BiDi elements to their spec definitions (#17781)
  • add objectOnly/preserveExtras/scalar-primitive BiDi schema signals (#17784)
  • construct the BiDi transport inside the domain from a connection (#17796)
  • route BiDiBridge navigation through the generated Protocol::BrowsingContext (#17785)
  • resolve spec runfiles via Bazel::Runfiles (#17810)
  • [build] standardize generated-file license and not to edit markers across generators (#17816)
  • validate nullable-constant BiDi params outbound (#17818)
  • [build] upgrade rules_ruby to 0.28.0 and drop vendored Bazel::Runfiles workaround (#17824)
  • [build] Merge vendor cddl files into shared BiDi schema and implement custom Firefox webExtension options (#17840)
  • [grid] honor client-advertised se:remoteUrl for reachable BiDi/CDP/VNC URLs (#17790)
  • tolerate and warn on missing required inbound BiDi fields, with SE_BIDI_STRICT to escalate (#17844)
  • remove deprecated FTP proxy support (#17846)
  • prevent CDP access with Firefox (#17849)
  • test matchers assert log entries by id and optional messages and match severity (#17848)
  • [bidi] Correct float/enum type fidelity in the shared schema and validate primitives outbound in Ruby (#17852)

... (truncated)

Commits
  • ca2a966 [build] Prepare for release of selenium-4.50.0 (#18105)
  • 27ef657 [rb] add bidi tests for recent spec updates
  • 76febdc [build] Automated Dependency Update (#18082)
  • 6f841aa [build] Automated CDDL Spec Update (#18075)
  • 52a288e [build] Automated Browser Version Update (major) with CDP (#18067)
  • acd7ce8 [rb] remove stale Windows pending guard from Firefox signed directory addon test
  • 748477d [rb] remove dead headless, browser and remote config_settings
  • 6ff202a [rb] fix flaky test by not applying timeouts to the setup navigation
  • 27c86e2 [build] add support for Mozilla's Commands fragment in the BiDi schema (#18071)
  • 59b28c4 [rb] fix nightly web extension spec failures on Safari and Windows
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 14:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.

…ates

Bumps the development-dependencies group with 2 updates in the / directory: [brakeman](https://github.com/presidentbeef/brakeman) and [selenium-webdriver](https://github.com/SeleniumHQ/selenium).


Updates `brakeman` from 8.0.6 to 8.1.0
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](presidentbeef/brakeman@v8.0.6...v8.1.0)

Updates `selenium-webdriver` from 4.45.0 to 4.50.0
- [Release notes](https://github.com/SeleniumHQ/selenium/releases)
- [Changelog](https://github.com/SeleniumHQ/selenium/blob/trunk/rb/CHANGES)
- [Commits](SeleniumHQ/selenium@selenium-4.45.0...selenium-4.50.0)

---
updated-dependencies:
- dependency-name: brakeman
  dependency-version: 8.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: selenium-webdriver
  dependency-version: 4.49.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/development-dependencies-e6d0d339d6 branch from 26c4693 to 11b1d53 Compare October 8, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant