Skip to content

Dependencies: 2026-04-07#405

Merged
lkacenja merged 8 commits intodevfrom
dep-2026-04-07
Apr 7, 2026
Merged

Dependencies: 2026-04-07#405
lkacenja merged 8 commits intodevfrom
dep-2026-04-07

Conversation

@lkacenja
Copy link
Copy Markdown
Contributor

@lkacenja lkacenja commented Apr 7, 2026

Summary

Addresses a backlog of Dependabot security alerts and folds in all open Dependabot PRs (#389#398, #401#403).


Rails & Rack (security)

Resolves ~30 Dependabot alerts across rack, activestorage, activesupport, actionview, actionpack, actiontext, json, nokogiri, loofah, and action_text-trix.

  • rails 8.1.1 → 8.1.3
  • rack 3.2.4 → 3.2.6
  • devise 4.9.4 → 5.0.3 (major version bump)

npm (security)

  • @hotwired/turbo-rails 8.0.12 → 8.0.23
  • tailwindcss 3.4.1 → 3.4.19 — fixes picomatch ReDoS; removes minimatch, brace-expansion, and yaml from the dependency tree entirely

Python components (security)

  • pillow 11.3.0 → 12.1.1 — out-of-bounds write in PSD image loading (document_inference)
  • requests 2.32.5 → 2.33.0 — insecure temp file reuse (document_inference)
  • black 25.1.0 → 26.3.1 — arbitrary file writes via cache file name (ci, evaluation)

Ruby gems (routine updates)

Closes stale Dependabot PRs #389#398. All gems were already at or beyond the PR targets after the Rails update pulled them in: aws-sdk-s3, aws-sdk-lambda, aws-sdk-secretsmanager, turbo-rails,
bootsnap, view_component, debug, standard, brakeman, thruster.


GitHub Actions

Closes Dependabot PRs #401#403.

  • aws-actions/configure-aws-credentials v5 → v6
  • actions/upload-artifact v6 → v7
  • opentofu/setup-opentofu v1 → v2

@lkacenja lkacenja changed the title Dep 2026 04 07 Dependencies: 2026-04-07 Apr 7, 2026
@lkacenja lkacenja self-assigned this Apr 7, 2026
@lkacenja lkacenja changed the base branch from main to dev April 7, 2026 20:25
@lkacenja lkacenja merged commit 04d2546 into dev Apr 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant