Closed dependabot-preview[bot] closed 5 years ago
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version
or @dependabot ignore this minor version
.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.
⚠️ Dependabot is rebasing this PR ⚠️
If you make any changes to it yourself then they will take precedence over the rebase.
Updates the requirements on sinatra to permit the latest version.
Changelog
*Sourced from [sinatra's changelog](https://github.com/sinatra/sinatra/blob/master/CHANGELOG.md).* > ## 2.0.5 / 2018-12-22 > > * Avoid FrozenError when params contains frozen value [#1506](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1506) by Kunpei Sakai > > * Add support for Erubi [#1494](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1494) by [**tkmru**](https://github.com/tkmru) > > * `IndifferentHash` monkeypatch warning improvements [#1477](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1477) by Mike Pastore > > * Improve development support and documentation and source code by Anusree Prakash, Jordan Owens, [**ceclinux**](https://github.com/ceclinux) and [**krororo**](https://github.com/krororo). > > ### sinatra-contrib > > * Add `flush` option to `content_for` [#1225](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1225) by Shota Iguchi > > * Drop activesupport dependency from sinatra-contrib [#1448](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1448) > > * Update `yield_content` to append default to ERB template buffer [#1500](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1500) by Jordan Owens > > ### rack-protection > > * Don't track the Accept-Language header by default [#1504](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1504) by Artem Chistyakov > > ## 2.0.4 / 2018-09-15 > > * Don't blow up when passing frozen string to `send_file` disposition [#1137](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1137) by Andrew Selder > > * Fix ubygems LoadError [#1436](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1436) by Pavel Rosický > > * Unescape regex captures [#1446](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1446) by Jordan Owens > > * Slight performance improvements for IndifferentHash [#1427](https://github-redirect.dependabot.com/sinatra/sinatra/pull/1427) by Mike Pastore > > * Improve development support and documentation and source code by Will Yang, Jake Craige, Grey Baker and Guilherme Goettems Schneider > > ## 2.0.3 / 2018-06-09 > > * Fix the backports gem regression [#1442](https://github-redirect.dependabot.com/sinatra/sinatra/issues/1442) by Marc-André Lafortune > > ## 2.0.2 / 2018-06-05 > > * Escape invalid query parameters [#1432](https://github-redirect.dependabot.com/sinatra/sinatra/issues/1432) by Kunpei Sakai > * The patch fixes [CVE-2018-11627](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11627). > > * Fix undefined method error for `Sinatra::RequiredParams` with hash key [#1431](https://github-redirect.dependabot.com/sinatra/sinatra/issues/1431) by Arpit Chauhan > > * Add xml content-types to valid html_types for Rack::Protection [#1413](https://github-redirect.dependabot.com/sinatra/sinatra/issues/1413) by Reenan Arbitrario > > * Encode route parameters using :default_encoding setting [#1412](https://github-redirect.dependabot.com/sinatra/sinatra/issues/1412) by Brian m. Carlson > > * Fix unpredictable behaviour from Sinatra::ConfigFile [#1244](https://github-redirect.dependabot.com/sinatra/sinatra/issues/1244) by John Hope > ... (truncated)Commits
- See full diff in [compare view](https://github.com/sinatra/sinatra/commits/v2.0.5)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) Finally, you can contact us by mentioning @dependabot.