Skip to content

chore(deps-dev): bump activesupport from 8.1.2 to 8.1.2.1#255

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/activesupport-8.1.2.1
Closed

chore(deps-dev): bump activesupport from 8.1.2 to 8.1.2.1#255
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/activesupport-8.1.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 23, 2026

Bumps activesupport from 8.1.2 to 8.1.2.1.

Release notes

Sourced from activesupport's releases.

8.1.2.1

Active Support

  • Reject scientific notation in NumberConverter

    [CVE-2026-33176]

    Jean Boussier

  • Fix SafeBuffer#% to preserve unsafe status

    [CVE-2026-33170]

    Jean Boussier

  • Improve performance of NumberToDelimitedConverter

    [CVE-2026-33169]

    Jean Boussier

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • Skip blank attribute names in tag helpers to avoid generating invalid HTML.

    [CVE-2026-33168]

    Mike Dalessio

Action Pack

  • Fix possible XSS in DebugExceptions middleware

    [CVE-2026-33167]

    John Hawthorn

... (truncated)

Changelog

Sourced from activesupport's changelog.

Rails 8.1.2.1 (March 23, 2026)

  • Reject scientific notation in NumberConverter

    [CVE-2026-33176]

    Jean Boussier

  • Fix SafeBuffer#% to preserve unsafe status

    [CVE-2026-33170]

    Jean Boussier

  • Improve performance of NumberToDelimitedConverter

    [CVE-2026-33169]

    Jean Boussier

Commits
  • 1db4b89 Preparing for 8.1.2.1 release
  • 1c7d1cf Update changelog
  • ec1a0e2 Improve performance of NumberToDelimitedConverter
  • 50d732a Fix SafeBuffer#% to preserve unsafe status
  • 19dbab5 NumberConverter: reject scientific notation
  • See full diff in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Mar 23, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 23, 2026 21:05
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Mar 23, 2026
Copilot AI review requested due to automatic review settings March 23, 2026 21:05
@dependabot dependabot bot added the ruby Pull requests that update ruby code label Mar 23, 2026
@dependabot dependabot bot review requested due to automatic review settings March 23, 2026 21:05
Copilot AI review requested due to automatic review settings April 7, 2026 14:32
@dependabot dependabot bot force-pushed the dependabot/bundler/activesupport-8.1.2.1 branch from 959f7e9 to 5796739 Compare April 7, 2026 14:32
@dependabot dependabot bot requested review from Copilot and removed request for Copilot April 7, 2026 14:32
@dependabot dependabot bot force-pushed the dependabot/bundler/activesupport-8.1.2.1 branch 2 times, most recently from 3fa1cc7 to 2e30d00 Compare April 12, 2026 16:29
@dependabot dependabot bot requested review from Copilot and removed request for Copilot April 12, 2026 16:29
Bumps [activesupport](https://github.com/rails/rails) from 8.1.2 to 8.1.2.1.
- [Release notes](https://github.com/rails/rails/releases)
- [Changelog](https://github.com/rails/rails/blob/v8.1.2.1/activesupport/CHANGELOG.md)
- [Commits](rails/rails@v8.1.2...v8.1.2.1)

---
updated-dependencies:
- dependency-name: activesupport
  dependency-version: 8.1.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings April 13, 2026 04:29
@dependabot dependabot bot force-pushed the dependabot/bundler/activesupport-8.1.2.1 branch from 2e30d00 to e98a6f7 Compare April 13, 2026 04:29
@dependabot dependabot bot review requested due to automatic review settings April 13, 2026 04:29
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Apr 14, 2026

Looks like activesupport is no longer a dependency, so this is no longer needed.

@dependabot dependabot bot closed this Apr 14, 2026
@dependabot dependabot bot deleted the dependabot/bundler/activesupport-8.1.2.1 branch April 14, 2026 04:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants