Skip to content

Bump the "all" group with 2 updates across multiple ecosystems#21120

Merged
MikeMcQuaid merged 3 commits intomainfrom
dependabot/all-f4ee3cd001
Nov 24, 2025
Merged

Bump the "all" group with 2 updates across multiple ecosystems#21120
MikeMcQuaid merged 3 commits intomainfrom
dependabot/all-f4ee3cd001

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Nov 21, 2025

Bumps the all group with 3 updates: actions/checkout, github/codeql-action and ruby/setup-ruby.

Updates actions/checkout from 5.0.0 to 6.0.0

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

V6.0.0

V5.0.1

V5.0.0

V4.3.1

V4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

v4.1.5

... (truncated)

Commits

Updates github/codeql-action from 4.31.3 to 4.31.4

Release notes

Sourced from github/codeql-action's releases.

v4.31.4

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.4 - 18 Nov 2025

No user facing changes.

See the full CHANGELOG.md for more information.

Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.31.4 - 18 Nov 2025

No user facing changes.

4.31.3 - 13 Nov 2025

  • CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
  • Update default CodeQL bundle version to 2.23.5. #3288

4.31.2 - 30 Oct 2025

No user facing changes.

4.31.1 - 30 Oct 2025

  • The add-snippets input has been removed from the analyze action. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.

4.31.0 - 24 Oct 2025

  • Bump minimum CodeQL bundle version to 2.17.6. #3223
  • When SARIF files are uploaded by the analyze or upload-sarif actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the upload-sarif action. For analyze, this may affect Advanced Setup for CodeQL users who specify a value other than always for the upload input. #3222

4.30.9 - 17 Oct 2025

  • Update default CodeQL bundle version to 2.23.3. #3205
  • Experimental: A new setup-codeql action has been added which is similar to init, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204

4.30.8 - 10 Oct 2025

No user facing changes.

4.30.7 - 06 Oct 2025

  • [v4+ only] The CodeQL Action now runs on Node.js v24. #3169

3.30.6 - 02 Oct 2025

  • Update default CodeQL bundle version to 2.23.2. #3168

3.30.5 - 26 Sep 2025

  • We fixed a bug that was introduced in 3.30.4 with upload-sarif which resulted in files without a .sarif extension not getting uploaded. #3160

... (truncated)

Commits
  • e12f017 Merge pull request #3312 from github/update-v4.31.4-70434f6dd
  • c9cb6f9 Update changelog for v4.31.4
  • 70434f6 Merge pull request #3311 from github/mbg/deps/bump-glob
  • 528362a Bump glob to at least 11.1.0
  • de12435 Merge pull request #3308 from github/mbg/pr-template/nov25
  • ffa63f0 Merge pull request #3307 from github/dependabot/github_actions/dot-github/wor...
  • 7bcdb4b Add additional options to PR template and clarify some
  • 07eae64 Merge pull request #3303 from github/mario-campos/v3-core-warning
  • e546fff Rebuild
  • c418a0f Bump ruby/setup-ruby
  • Additional commits viewable in compare view

Updates ruby/setup-ruby from 1.267.0 to 1.268.0

Release notes

Sourced from ruby/setup-ruby's releases.

v1.268.0

What's Changed

Full Changelog: ruby/setup-ruby@v1.267.0...v1.268.0

Commits

Bumps the all group with 3 updates in the /Library/Homebrew directory: minitest, sorbet-static-and-runtime and ruby-lsp.

Updates minitest from 5.26.1 to 5.26.2

Changelog

Sourced from minitest's changelog.

=== 5.26.2 / 2025-11-17

  • 5 bug fixes:

    • Bumped minimum ruby to 3.1.
    • Alias Spec#name to #inspect for cleaner output in repls.
    • Fix pathing for Hoe::Minitest initialization to be more generic.
    • Fixed refute_in_epsilon to use min of abs values. (wtn)
    • Improved options processing and usage output to be more clear.
Commits
  • 25f78c0 prepped for release
  • 1284a3f Dropped extra 2.7 compatibility code.
  • adfb01d Dropped extra 2.7 compatibility code.
  • aa1c3fa - Fix pathing for Hoe::Minitest initialization to be more generic.
  • cb3a345 - Bumped minimum ruby to 3.1.
  • 1f47bc6 - Fixed refute_in_epsilon to use min of abs values. (wtn)
  • a52e727 Fuuuuck I am SO tired of ruby 2.7!
  • 33259e4 - Alias Spec#name to #inspect for cleaner output in repls.
  • e2bc84c - Improved options processing and usage output to be more clear.
  • See full diff in compare view

Updates sorbet-static-and-runtime from 0.6.12765 to 0.6.12783

Release notes

Sourced from sorbet-static-and-runtime's releases.

sorbet 0.6.12782.20251120114804-4b9e99ee9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12782', :group => :development
gem 'sorbet-runtime', '0.6.12782'

sorbet 0.6.12781.20251120114623-ecf459fa9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12781', :group => :development
gem 'sorbet-runtime', '0.6.12781'

sorbet 0.6.12780.20251119094043-748358de2

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12780', :group => :development
gem 'sorbet-runtime', '0.6.12780'

sorbet 0.6.12779.20251118153111-36c74af58

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12779', :group => :development
gem 'sorbet-runtime', '0.6.12779'

sorbet 0.6.12778.20251117162106-0758aa11e

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12778', :group => :development
gem 'sorbet-runtime', '0.6.12778'

sorbet 0.6.12777.20251117151913-a939cc718

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12777', :group => :development
gem 'sorbet-runtime', '0.6.12777'

sorbet 0.6.12776.20251117151655-ef92f1d7c

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12776', :group => :development
gem 'sorbet-runtime', '0.6.12776'

sorbet 0.6.12775.20251117141854-4452364a6

... (truncated)

Commits

Updates ruby-lsp from 0.26.3 to 0.26.4

Release notes

Sourced from ruby-lsp's releases.

v0.26.4

🐛 Bug Fixes

Commits

Updates sorbet-runtime from 0.6.12765 to 0.6.12783

Release notes

Sourced from sorbet-runtime's releases.

sorbet 0.6.12782.20251120114804-4b9e99ee9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12782', :group => :development
gem 'sorbet-runtime', '0.6.12782'

sorbet 0.6.12781.20251120114623-ecf459fa9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12781', :group => :development
gem 'sorbet-runtime', '0.6.12781'

sorbet 0.6.12780.20251119094043-748358de2

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12780', :group => :development
gem 'sorbet-runtime', '0.6.12780'

sorbet 0.6.12779.20251118153111-36c74af58

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12779', :group => :development
gem 'sorbet-runtime', '0.6.12779'

sorbet 0.6.12778.20251117162106-0758aa11e

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12778', :group => :development
gem 'sorbet-runtime', '0.6.12778'

sorbet 0.6.12777.20251117151913-a939cc718

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12777', :group => :development
gem 'sorbet-runtime', '0.6.12777'

sorbet 0.6.12776.20251117151655-ef92f1d7c

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12776', :group => :development
gem 'sorbet-runtime', '0.6.12776'

sorbet 0.6.12775.20251117141854-4452364a6

... (truncated)

Commits

Updates sorbet from 0.6.12765 to 0.6.12783

Release notes

Sourced from sorbet's releases.

sorbet 0.6.12782.20251120114804-4b9e99ee9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12782', :group => :development
gem 'sorbet-runtime', '0.6.12782'

sorbet 0.6.12781.20251120114623-ecf459fa9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12781', :group => :development
gem 'sorbet-runtime', '0.6.12781'

sorbet 0.6.12780.20251119094043-748358de2

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12780', :group => :development
gem 'sorbet-runtime', '0.6.12780'

sorbet 0.6.12779.20251118153111-36c74af58

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12779', :group => :development
gem 'sorbet-runtime', '0.6.12779'

sorbet 0.6.12778.20251117162106-0758aa11e

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12778', :group => :development
gem 'sorbet-runtime', '0.6.12778'

sorbet 0.6.12777.20251117151913-a939cc718

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12777', :group => :development
gem 'sorbet-runtime', '0.6.12777'

sorbet 0.6.12776.20251117151655-ef92f1d7c

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12776', :group => :development
gem 'sorbet-runtime', '0.6.12776'

sorbet 0.6.12775.20251117141854-4452364a6

... (truncated)

Commits

Updates sorbet-static from 0.6.12765 to 0.6.12783

Release notes

Sourced from sorbet-static's releases.

sorbet 0.6.12782.20251120114804-4b9e99ee9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12782', :group => :development
gem 'sorbet-runtime', '0.6.12782'

sorbet 0.6.12781.20251120114623-ecf459fa9

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12781', :group => :development
gem 'sorbet-runtime', '0.6.12781'

sorbet 0.6.12780.20251119094043-748358de2

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12780', :group => :development
gem 'sorbet-runtime', '0.6.12780'

sorbet 0.6.12779.20251118153111-36c74af58

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12779', :group => :development
gem 'sorbet-runtime', '0.6.12779'

sorbet 0.6.12778.20251117162106-0758aa11e

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12778', :group => :development
gem 'sorbet-runtime', '0.6.12778'

sorbet 0.6.12777.20251117151913-a939cc718

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12777', :group => :development
gem 'sorbet-runtime', '0.6.12777'

sorbet 0.6.12776.20251117151655-ef92f1d7c

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.12776', :group => :development
gem 'sorbet-runtime', '0.6.12776'

sorbet 0.6.12775.20251117141854-4452364a6

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added dependencies Bumping Gemfile dependencies github_actions Pull requests that update GitHub Actions code labels Nov 21, 2025
@MikeMcQuaid
Copy link
Copy Markdown
Member

@cho-m Looks like the right bundler isn't found again. This was working last week so I suspect due to the PATH changes.

@cho-m
Copy link
Copy Markdown
Member

cho-m commented Nov 21, 2025

@cho-m Looks like the right bundler isn't found again. This was working last week so I suspect due to the PATH changes.

vendor-gems also used to run Homebrew.install_bundler! so it may need the environment set up (Homebrew.setup_gem_environment!)

Can try restoring behavior in #21121

@cho-m cho-m force-pushed the dependabot/all-f4ee3cd001 branch from 1bceda0 to d55cd91 Compare November 21, 2025 16:34
@cho-m
Copy link
Copy Markdown
Member

cho-m commented Nov 21, 2025

Vendor Gems works now - https://github.com/Homebrew/brew/actions/runs/19577023970/job/56064991911?pr=21120

Not sure on why newer Sorbet isn't getting found:

Fetching sorbet-runtime 0.6.12783
Installing sorbet-runtime 0.6.12783
...
Bundle complete! 44 Gemfile dependencies, 33 gems now installed.
Bundled gems are installed into `../../../../linuxbrew/.linuxbrew/Homebrew/Library/Homebrew/vendor/bundle`
Removing sorbet-runtime (0.6.12765)
1 installed gem you directly depend on is looking for funding.
  Run `bundle fund` for details
<internal:/home/linuxbrew/.linuxbrew/Homebrew/Library/Homebrew/vendor/portable-ruby/3.4.7/lib/ruby/3.4.0/rubygems/core_ext/kernel_require.rb>:37:in 'Kernel#require': cannot load such file -- sorbet-runtime (LoadError)

I do see vendor/bundle/bundler/setup.rb still references old version if the gem install is triggered via another brew command other than brew vendor-gems

@MikeMcQuaid
Copy link
Copy Markdown
Member

@cho-m Think the vendor-gems workflow dispatch just needed run. Seems to be working now it's committed those changes.

@MikeMcQuaid MikeMcQuaid force-pushed the dependabot/all-f4ee3cd001 branch from 8554f9d to 539bf78 Compare November 23, 2025 16:05
@cho-m
Copy link
Copy Markdown
Member

cho-m commented Nov 23, 2025

  Warning: Some installed casks are deprecated or disabled.
  You should find replacements for the following casks:
    session-manager-plugin

Looks like we just deprecated this (Homebrew/homebrew-cask@8fb478e) but GitHub installs it on their runners: https://github.com/actions/runner-images/blob/main/images/macos/scripts/build/install-aws-tools.sh#L17-L18


Stack trace for other failure:

/opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov/lines_classifier.rb:36:in 'IO.foreach': No such file or directory @ rb_sysopen - /opt/homebrew/Library/Homebrew/cmd/rbcmd.rb (Errno::ENOENT)
        from /opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov/lines_classifier.rb:36:in 'Enumerator#each'
        from /opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov/lines_classifier.rb:36:in 'Enumerable#map'
        from /opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov/lines_classifier.rb:36:in 'SimpleCov::LinesClassifier#classify'
        from /opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov/simulate_coverage.rb:22:in 'SimpleCov::SimulateCoverage.call'
        from /opt/homebrew/Library/Homebrew/.simplecov:49:in 'block (3 levels) in <top (required)>'
        from /opt/homebrew/Library/Homebrew/.simplecov:47:in 'Array#each'
        from /opt/homebrew/Library/Homebrew/.simplecov:47:in 'block (2 levels) in <top (required)>'
        from /opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov.rb:189:in 'SimpleCov.run_exit_tasks!'
        from /opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov.rb:179:in 'SimpleCov.at_exit_behavior'
        from /opt/homebrew/Library/Homebrew/vendor/bundle/ruby/3.4.0/gems/simplecov-0.22.0/lib/simplecov/defaults.rb:30:in 'block in <top (required)>'

Looks like a parallel test issue where timing of commands_spec.rb can cause extra temporary Ruby files to be detected.

@cho-m
Copy link
Copy Markdown
Member

cho-m commented Nov 23, 2025

dependabot bot and others added 3 commits November 24, 2025 14:16
Bumps the all group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [github/codeql-action](https://github.com/github/codeql-action) and [ruby/setup-ruby](https://github.com/ruby/setup-ruby).


Updates `actions/checkout` from 5.0.0 to 6.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@08c6903...1af3b93)

Updates `github/codeql-action` from 4.31.3 to 4.31.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@014f16e...e12f017)

Updates `ruby/setup-ruby` from 1.267.0 to 1.268.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](ruby/setup-ruby@d5126b9...8aeb6ff)
build(deps): bump the all group across 1 directory with 6 updates

Bumps the all group with 3 updates in the /Library/Homebrew directory: [minitest](https://github.com/minitest/minitest), [sorbet-static-and-runtime](https://github.com/sorbet/sorbet) and [ruby-lsp](https://github.com/Shopify/ruby-lsp).


Updates `minitest` from 5.26.1 to 5.26.2
- [Changelog](https://github.com/minitest/minitest/blob/master/History.rdoc)
- [Commits](minitest/minitest@v5.26.1...v5.26.2)

Updates `sorbet-static-and-runtime` from 0.6.12765 to 0.6.12783
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

Updates `ruby-lsp` from 0.26.3 to 0.26.4
- [Release notes](https://github.com/Shopify/ruby-lsp/releases)
- [Commits](Shopify/ruby-lsp@v0.26.3...v0.26.4)

Updates `sorbet-runtime` from 0.6.12765 to 0.6.12783
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

Updates `sorbet` from 0.6.12765 to 0.6.12783
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

Updates `sorbet-static` from 0.6.12765 to 0.6.12783
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all
- dependency-name: github/codeql-action
  dependency-version: 4.31.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: ruby/setup-ruby
  dependency-version: 1.268.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: minitest
  dependency-version: 5.26.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: sorbet-static-and-runtime
  dependency-version: 0.6.12783
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: ruby-lsp
  dependency-version: 0.26.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: sorbet-runtime
  dependency-version: 0.6.12783
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: sorbet
  dependency-version: 0.6.12783
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: sorbet-static
  dependency-version: 0.6.12783
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@botantony botantony force-pushed the dependabot/all-f4ee3cd001 branch from 539bf78 to de6702f Compare November 24, 2025 13:16
@MikeMcQuaid MikeMcQuaid added this pull request to the merge queue Nov 24, 2025
Merged via the queue into main with commit 2255e51 Nov 24, 2025
43 checks passed
@MikeMcQuaid MikeMcQuaid deleted the dependabot/all-f4ee3cd001 branch November 24, 2025 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Bumping Gemfile dependencies github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants