Skip to content

Conversation

@dependabot-preview
Copy link

Bumps rubocop from 0.32.1 to 0.64.0. This update includes security fixes.

Vulnerabilities fixed

Sourced from The Ruby Advisory Database.

RuboCop: insecure use of /tmp
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local
users to exploit this to tamper with cache files belonging to other users.

Patched versions: >= 0.49.0
Unaffected versions: none

Release notes

Sourced from rubocop's releases.

RuboCop 0.64

New features

  • #6704: Add new Rails/ReflectionClassName cop. ([Bhacaz][])
  • #6643: Support AllowParenthesesInCamelCaseMethod option on Style/MethodCallWithArgsParentheses omit_parentheses. ([dazuma][])

Bug fixes

  • #6254: Fix Layout/RescueEnsureAlignment for non-local assignments. ([marcotc][])
  • #6648: Fix auto-correction of Style/EmptyLiteral when Hash.new is passed as the first argument to super. ([rrosenblum][])
  • #6351: Fix a false positive for Layout/ClosingParenthesisIndentation when first argument is multiline. ([antonzaytsev][])
  • #6689: Support more complex argument patterns on Rails/Validation auto-correction. ([r7kamura][])
  • #6668: Fix autocorrection for Style/UnneededCondition when conditional has the unless form. ([mvz][])
  • #6382: Fix Layout/IndentationWidth with Layout/EndAlignment set to start_of_line. ([dischorde][], [siegfault][], [mhelmetag][])
  • #6710: Fix Naming/MemoizedInstanceVariableName on method starts with underscore. ([pocke][])
  • #6722: Fix an error for Style/OneLineConditional when then branch has no body. ([koic][])
  • #6702: Fix TrailingComma regression where heredoc with commas caused false positives. ([abrom][])
  • #6737: Fix an incorrect auto-correct for Rails/LinkToBlank when link_to method arguments are enclosed in parentheses. ([koic][])
  • #6720: Fix detection of :native line ending for Layout/EndOfLine on JRuby. ([enkessler][])

Changes

  • #6597: Style/LineEndConcatenation is now known to be unsafe for auto-correct. ([jaredbeck][])
  • #6725: Mark Style/SymbolProc as unsafe for auto-correct. ([drenmi][])
  • #6708: Make Style/CommentedKeyword allow the :yields: RDoc comment. ([bquorning][])
  • #6749: Make some cops aware of safe navigation operator. ([hoshinotsuyoshi][])

[Bhacaz]: https://github.com/Bhacaz
[dazuma]: https://github.com/dazuma
[marcotc]: https://github.com/marcotc
[rrosenblum]: https://github.com/rrosenblum
[antonzaytsev]: https://github.com/antonzaytsev
[r7kamura]: https://github.com/r7kamura
[mvz]: https://github.com/mvz
[dischorde]: https://github.com/dischorde
[siegfault]: https://github.com/siegfault
[mhelmetag]: https://github.com/mhelmetag
[pocke]: https://github.com/pocke
[koic]: https://github.com/koic
[abrom]: https://github.com/abrom
[enkessler]: https://github.com/enkessler
[jaredbeck]: https://github.com/jaredbeck
[drenmi]: https://github.com/drenmi
[bquorning]: https://github.com/bquorning
[hoshinotsuyoshi]: https://github.com/hoshinotsuyoshi

RuboCop 0.63.1

Bug fixes

  • #6678: Fix Lint/DisjunctiveAssignmentInConstructor when it finds an empty constructor. ([rmm5t][])
... (truncated)
Changelog

Sourced from rubocop's changelog.

0.64.0 (2019-02-10)

New features

  • #6704: Add new Rails/ReflectionClassName cop. ([Bhacaz][])
  • #6643: Support AllowParenthesesInCamelCaseMethod option on Style/MethodCallWithArgsParentheses omit_parentheses. ([dazuma][])

Bug fixes

  • #6254: Fix Layout/RescueEnsureAlignment for non-local assignments. ([marcotc][])
  • #6648: Fix auto-correction of Style/EmptyLiteral when Hash.new is passed as the first argument to super. ([rrosenblum][])
  • #6351: Fix a false positive for Layout/ClosingParenthesisIndentation when first argument is multiline. ([antonzaytsev][])
  • #6689: Support more complex argument patterns on Rails/Validation auto-correction. ([r7kamura][])
  • #6668: Fix autocorrection for Style/UnneededCondition when conditional has the unless form. ([mvz][])
  • #6382: Fix Layout/IndentationWidth with Layout/EndAlignment set to start_of_line. ([dischorde][], [siegfault][], [mhelmetag][])
  • #6710: Fix Naming/MemoizedInstanceVariableName on method starts with underscore. ([pocke][])
  • #6722: Fix an error for Style/OneLineConditional when then branch has no body. ([koic][])
  • #6702: Fix TrailingComma regression where heredoc with commas caused false positives. ([abrom][])
  • #6737: Fix an incorrect auto-correct for Rails/LinkToBlank when link_to method arguments are enclosed in parentheses. ([koic][])
  • #6720: Fix detection of :native line ending for Layout/EndOfLine on JRuby. ([enkessler][])

Changes

  • #6597: Style/LineEndConcatenation is now known to be unsafe for auto-correct. ([jaredbeck][])
  • #6725: Mark Style/SymbolProc as unsafe for auto-correct. ([drenmi][])
  • #6708: Make Style/CommentedKeyword allow the :yields: RDoc comment. ([bquorning][])
  • #6749: Make some cops aware of safe navigation operator. ([hoshinotsuyoshi][])

0.63.1 (2019-01-22)

Bug fixes

  • #6678: Fix Lint/DisjunctiveAssignmentInConstructor when it finds an empty constructor. ([rmm5t][])
  • Do not attempt to auto-correct mass assignment or optional assignment in Rails/RelativeDateConstant. ([rrosenblum][])
  • Fix auto-correction of Style/WordArray and Style/SymbolArray when all elements are on separate lines and there is a trailing comment after the closing bracket. ([rrosenblum][])
  • Fix an exception that occurs when auto-correcting Layout/ClosingParenthesesIndentation when there are no arguments. ([rrosenblum][])

0.63.0 (2019-01-16)

New features

  • #6604: Add auto-correct support to Rails/LinkToBlank. ([Intrepidd][])
  • #6660: Add new Rails/IgnoredSkipActionFilterOption cop. ([wata727][])
  • #6363: Allow Style/YodaCondition cop to be configured to enforce yoda conditions. ([tejasbubane][])
  • #6150: Add support to enforce disabled cops to be executed. ([roooodcastro][])
  • #6596: Add new Rails/BelongsTo cop with auto-correct for Rails >= 5. ([petehamilton][])

Bug fixes

  • #6627: Fix handling of hashes in trailing comma. ([abrom][])
... (truncated)
Commits
  • eb1caef Merge pull request #6753 from Drenmi/release/0-64-0
  • 7c6917d Cut 0.64.0
  • 548bf43 Merge pull request #6749 from hoshinotsuyoshi/aware_safe_navigator_in_some_cops
  • 48415e2 Add a test case for modifying RuboCop::Cop::CheckAssignment#extract_rhs
  • 0ce168e Update CHANGELOG.md
  • fcd785c Make Style/TrailingCommaInArguments aware of safe navigation operator
  • 82402bc Make Style/StringMethods aware of safe navigation operator
  • 4f6c20b Make Style/Send aware of safe navigation operator
  • 5fc114c Make Style/PreferredHashMethods aware of safe navigation operator
  • a285622 Make Style/NestedParenthesizedCalls aware of safe navigation operator
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Finally, you can contact us by mentioning @dependabot.

Bumps [rubocop](https://github.com/rubocop-hq/rubocop) from 0.32.1 to 0.64.0. **This update includes security fixes.**
- [Release notes](https://github.com/rubocop-hq/rubocop/releases)
- [Changelog](https://github.com/rubocop-hq/rubocop/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop@v0.32.1...v0.64.0)

Signed-off-by: dependabot[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Feb 12, 2019
@dependabot-preview
Copy link
Author

Superseded by #13.

@dependabot-preview dependabot-preview bot deleted the dependabot/bundler/rubocop-0.64.0 branch February 20, 2019 05:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants