Skip to content

Bump brakeman from 5.0.1 to 5.2.2#997

Closed
dependabot[bot] wants to merge 1 commit into
mathtodonfrom
dependabot/bundler/brakeman-5.2.2
Closed

Bump brakeman from 5.0.1 to 5.2.2#997
dependabot[bot] wants to merge 1 commit into
mathtodonfrom
dependabot/bundler/brakeman-5.2.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 11, 2022

Copy link
Copy Markdown

Bumps brakeman from 5.0.1 to 5.2.2.

Release notes

Sourced from brakeman's releases.

5.2.2

  • Respect equality in if conditions (#1683)
  • Update message for unsafe reflection (Pedro Baracho)
  • Handle nil when joining values (Dan Buettner)
  • Add additional String methods for SQL injection check (#1669)
  • Update ruby_parser for Ruby 3.1 support (Merek Skubela)

5.2.1

  • Add warning codes for EOL software warnings (#1671)

5.2.0

  • Initial Rails 7 support (#1653)
  • Require Ruby 2.5.0+ (#1649)
  • Fix issue with calls to foo.root in routes (#1640)
  • Ignore I18n.locale in SQL queries (#1597)
  • Do not treat sanitize_sql_like as safe
  • Add new checks for unsupported Ruby and Rails version
  • Bundled version of ruby_parser updated to 3.18.1

5.1.2

  • Updated ruby_parser (Ryan Davis)
  • Fix issue where the previous output is still visible (Jason Frey)
  • Handle cases where enums are not symbols (#1627)
  • Support newer Haml with ::Haml::AttributeBuilder.build
  • Fix sorting with nil line numbers

5.1.1

  • Unrefactor IgnoreConfig's use of Brakeman::FilePath

(Fixes bugs with -I and also relative paths for -i.)

5.1.0

  • Report Formats
  • Performance
    • Read and parse files in parallel
  • Ruby Interpretation
    • Initial support for ActiveRecord enums (#1492)
    • Interprocedural dataflow from very simple class methods
    • Support Array#fetch and Hash#fetch (#1571)
    • Support Array#push
    • Support Array#*
    • Better Array#join support
    • Support Hash#values and Hash#values_at
    • Support Hash#include?
  • SQL Injection
    • Update SQL injection check for Rails 6.0/6.1

... (truncated)

Changelog

Sourced from brakeman's changelog.

5.2.2 - 2022-04-06

  • Update ruby_parser for Ruby 3.1 support (Merek Skubela)
  • Handle nil when joining values (Dan Buettner)
  • Update message for unsafe reflection (Pedro Baracho)
  • Add additional String methods for SQL injection check
  • Respect equality in if conditions

5.2.1 - 2022-01-30

  • Add warning codes for EOL software warnings

5.2.0 - 2021-12-15

  • Initial Rails 7 support
  • Require Ruby 2.5.0+
  • Fix issue with calls to foo.root in routes
  • Ignore I18n.locale in SQL queries
  • Do not treat sanitize_sql_like as safe
  • Add new checks for unsupported Ruby and Rails versions

5.1.2 - 2021-10-28

  • Handle cases where enums are not symbols
  • Support newer Haml with ::Haml::AttributeBuilder.build
  • Fix issue where the previous output is still visible (Jason Frey)
  • Fix warning sorting with nil line numbers
  • Update for latest RubyParser (Ryan Davis)

5.1.1 - 2021-07-19

  • Unrefactor IgnoreConfig's use of Brakeman::FilePath

5.1.0 - 2021-07-19

  • Initial support for ActiveRecord enums
  • Support Hash#include?
  • Interprocedural dataflow from very simple class methods
  • Fix SARIF report when checks have no description (Eli Block)
  • Add ignored warnings to SARIF report (Eli Block)
  • Add --sql-safe-methods option (Esty Scheiner)
  • Update SQL injection check for Rails 6.0/6.1
  • Fix false positive in command injection with Open3.capture (Richard Fitzgerald)
  • Fix infinite loop on mixin self-includes (Andrew Szczepanski)
  • Ignore dates in SQL
  • Refactor cookie?/param? methods (Keenan Brock)
  • Ignore renderables in dynamic render path check (Brad Parker)
  • Support Array#push
  • Better Array#join support
  • Adjust copy of --interactive menu (Elia Schito)

... (truncated)

Commits
  • 96c8e82 Bump to 5.2.2
  • 4ddbc03 Merge pull request #1697 from presidentbeef/fix_date_related_tests
  • e541dd3 Fix a couple date-related tests
  • a64ea72 Merge pull request #1695 from sqbell/basic-ruby-3.1-support
  • 0d2a488 Add basic Ruby 3.1 syntax
  • 52df8b6 Bump ruby_parser to support Ruby 3.1
  • 5a1eb49 Merge pull request #1686 from Capncavedan/patch-nil-method-error-in-alias-pro...
  • 243012a Merge pull request #1670 from pedropb/update_copy_on_unsafe_reflection_check
  • ccde22b Patch to avoid issue with nil method call in alias_processor join_item
  • 177cb44 Update copy on unsafe reflection error message
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [brakeman](https://github.com/presidentbeef/brakeman) from 5.0.1 to 5.2.2.
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](presidentbeef/brakeman@v5.0.1...v5.2.2)

---
updated-dependencies:
- dependency-name: brakeman
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Apr 11, 2022
@dependabot @github

dependabot Bot commented on behalf of github May 2, 2022

Copy link
Copy Markdown
Author

Superseded by #1015.

@dependabot dependabot Bot closed this May 2, 2022
@dependabot dependabot Bot deleted the dependabot/bundler/brakeman-5.2.2 branch May 2, 2022 06:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants