Skip to content

Bump rails from 8.1.2 to 8.1.3 - #16

Open
dependabot[bot] wants to merge 29 commits into
mainfrom
dependabot/bundler/rails-8.1.3
Open

Bump rails from 8.1.2 to 8.1.3#16
dependabot[bot] wants to merge 29 commits into
mainfrom
dependabot/bundler/rails-8.1.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 31, 2026

Copy link
Copy Markdown

Bumps rails from 8.1.2 to 8.1.3.

Release notes

Sourced from rails's releases.

8.1.3

Active Support

  • Fix JSONGemCoderEncoder to correctly serialize custom object hash keys.

    When hash keys are custom objects whose as_json returns a Hash, the encoder now calls to_s on the original key object instead of on the as_json result.

    Before: hash = {CustomKey.new(123) => "value"} hash.to_json # => {"{:id=>123}":"value"}

    After: hash.to_json # => {"custom_123":"value"}

    Dan Sharp

  • Fix inflections to better handle overlapping acronyms.

    ActiveSupport::Inflector.inflections(:en) do |inflect|
      inflect.acronym "USD"
      inflect.acronym "USDC"
    end
    "USDC".underscore # => "usdc"

    Said Kaldybaev

  • Silence Dalli 4.0+ warning when using ActiveSupport::Cache::MemCacheStore.

    zzak

Active Model

  • Fix Ruby 4.0 delegator warning when calling inspect on attributes.

    Hammad Khan

  • Fix NoMethodError when deserialising Type::Integer objects marshalled under Rails 8.0.

    The performance optimisation that replaced @range with @max/@min broke Marshal compatibility. Objects serialised under 8.0 (with @range) and deserialised under 8.1 (expecting @max/@min) would crash with undefined method '<=' for nil because Marshal.load restores instance variables without calling initialize.

... (truncated)

Commits
  • fa8f081 Preparing for 8.1.3 release
  • 63cef3d Merge branch '8-1-sec' into 8-1-stable
  • 1db4b89 Preparing for 8.1.2.1 release
  • 1c7d1cf Update changelog
  • e91694b Update CHANGELOG (8.1 only)
  • 6752711 Fix XSS in debug exceptions copy-to-clipboard
  • 63f5ad8 Skip blank attribute names in Action View tag helpers
  • 8c9676b Prevent glob injection in ActiveStorage DiskService#delete_prefixed
  • 9b06fbc Prevent path traversal in ActiveStorage DiskService
  • ec1a0e2 Improve performance of NumberToDelimitedConverter
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

sansari and others added 29 commits February 10, 2026 15:19
- Enable PWA routes (manifest + service worker)
- Fix manifest: add short_name, proper theme/background colors
- Activate minimal service worker for PWA qualification
- Add badge Stimulus controller: fetches dashboard JSON, calls
  navigator.setAppBadge() with overdue + due_soon count, polls
  every 5 min, updates on visibilitychange
- Add notification permission banner for iOS badge support
- Create CHANGELOG.md with project history
- Create AGENTS.md with notes for future Claude Code sessions

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Create plans/ directory with reconstructed plans for all 6 major
  phases of the project (001-initial-build through 006-documentation-workflow)
- Update CHANGELOG.md to reference plan files in each entry
- Update SPEC.md to reflect current app behavior (2-week window,
  log page, PWA support, Railway deployment details)
- Add Documentation Workflow section to CLAUDE.md establishing
  conventions: plans committed to repo, changelog references plans,
  spec stays in sync, CLAUDE.md documents workflow

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Server-side push via web-push gem with VAPID auth. BadgeNotificationJob
runs every 12 hours, sends push when task count changes. Service worker
updates badge even when app is closed. Job self-reports failures via push.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Entrypoint checked last 2 args but CMD has 4 args, so db:prepare
never ran on deploy. Now checks first 2 args ($1, $2) instead.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Priority was unused and not meaningful. Drop the column, remove validation,
helper, view references, and tests.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Add a green "Done" button to each task row on the dashboard and a
"Mark Done" button on the task detail page. Both use the existing
POST /tasks/:id/complete endpoint with a Turbo confirmation dialog.
The complete action now uses redirect_back so clicking Done from the
dashboard returns to the dashboard instead of navigating away.

https://claude.ai/code/session_01Ta8kLsYYDH1xYJaiQvBmN2
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
- Fix RuboCop Layout/SpaceInsideArrayLiteralBrackets errors by removing spaces inside array brackets
- Fix test failures by using dig() to safely access VAPID credentials that may not be set in test environment

Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
- Add spaces inside array brackets per rubocop-rails-omakase style guide
- Changed [:foo] to [ :foo ] in 4 controller files

Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
…ty line

- Disable Layout/SpaceInsideArrayLiteralBrackets in .rubocop.yml
- Remove extra empty line before class end in maintenance_task_test.rb

Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Co-authored-by: sansari <105090+sansari@users.noreply.github.com>
Bumps [rails](https://github.com/rails/rails) from 8.1.2 to 8.1.3.
- [Release notes](https://github.com/rails/rails/releases)
- [Commits](rails/rails@v8.1.2...v8.1.3)

---
updated-dependencies:
- dependency-name: rails
  dependency-version: 8.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Mar 31, 2026
@dependabot dependabot Bot added ruby Pull requests that update ruby code dependencies Pull requests that update a dependency file labels Mar 31, 2026
@sansari
sansari force-pushed the main branch 2 times, most recently from cb219e1 to 695229c Compare June 25, 2026 06:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants