Skip to content

Bump the major-updates group across 1 directory with 8 updates - #4784

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/major-updates-0347291dba
Open

Bump the major-updates group across 1 directory with 8 updates#4784
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/major-updates-0347291dba

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the major-updates group with 8 updates in the / directory:

Package From To
discard 1.4.0 2.0.0
haml 5.2.2 7.3.1
i18n-js 3.9.2 4.2.4
shakapacker 9.5.0 10.3.1
rspec-rails 6.1.5 8.0.4
shoulda-matchers 7.0.1 8.0.1
simplecov 0.22.0 1.1.1
puma 7.2.1 8.0.2

Updates discard from 1.4.0 to 2.0.0

Changelog

Sourced from discard's changelog.

Version 2.0.0

Release date: 2026-05-27

  • Require ActiveRecord >= 7.0; drop support for Rails 6.x and earlier
  • Wrap #discard / #undiscard in a transaction so callback exceptions roll back the DB write (#84, #77)
Commits
  • cdeb3d4 Version 2.0.0
  • 94effaf Document current interaction with validations
  • 7a0a61c Merge pull request #124 from jarednorman/pr-84
  • 60fb990 Wrap discard methods in a transaction
  • 0e68168 CI: drop Ruby 3.1, add Ruby 3.4
  • c1d5888 Raise ActiveRecord floor to 7.0
  • 7a9417d Merge pull request #116 from okuramasafumi/fix-ci
  • f7dd775 Merge pull request #118 from SuperGoodSoft/fix-tests
  • 26f3113 Update readme to have correct test command
  • 4340d3f Fix tests
  • Additional commits viewable in compare view

Updates haml from 5.2.2 to 7.3.1

Release notes

Sourced from haml's releases.

v7.3.1

What's Changed

New Contributors

Full Changelog: haml/haml@v7.3.0...v7.3.1

v7.3.0

What's Changed

New Contributors

Full Changelog: haml/haml@v7.2.2...v7.3.0

v7.2.2

What's Changed

New Contributors

Full Changelog: haml/haml@v7.2.1...v7.2.2

v7.2.1

What's Changed

New Contributors

Full Changelog: haml/haml@v7.2.0...v7.2.1

v7.2.0

What's Changed

New Contributors

Full Changelog: haml/haml@v7.1.0...v7.2.0

v7.1.0

What's Changed

... (truncated)

Changelog

Sourced from haml's changelog.

7.3.1

  • Keep Prism-derived fragments in the source encoding, fixing Encoding::CompatibilityError on an ASCII-8BIT template source with non-ASCII characters (regression in 7.3.0) haml/haml#1218

7.3.0

  • Replace Ripper with Prism haml/haml#1214
    • Interpolate #@ivar, #$gvar and #@@cvar in string literals instead of dropping them
    • Keep an escaped delimiter of a percent literal, so = %q{a\}b} renders a}b
    • Deprecate Haml::AttributeParser.available?, which is now always true and will be removed in the future

7.2.2

7.2.1

  • Do not rely on Ripper quirk in parsing old-style Haml attributes haml/haml#1212

7.2.0

7.1.0

  • Support xhtml format for boolean nested data attributes haml/haml#1200

7.0.2

7.0.1

7.0.0

6.4.0

... (truncated)

Commits
  • 3e7adad Version 7.3.1
  • 554ea24 Keep Prism-derived fragments in the source encoding (#1219)
  • b3dadcb Version 7.3.0
  • d48f109 Add a changelog entry for the Prism migration
  • d897efd Let the plain filter tolerate Ruby that does not parse
  • 4725f2f Parse template Ruby as a partial script
  • 1fa5f59 Replace the remaining Ripper usages with Prism
  • f6e18da Replace Ripper with Prism in syntax and string literal checks
  • 0c549c3 Add info to metadata (#1213)
  • 8f293ac Version 7.2.2
  • Additional commits viewable in compare view

Updates i18n-js from 3.9.2 to 4.2.4

Changelog

Sourced from i18n-js's changelog.

Changelog

v5.0.0.rc1 - Jun 02, 2026

  • [Added] embed_fallback_translations plugin now supports I18n.fallbacks, and will switch to it automatically if you're using a backend that includes the I18n::Backend::Fallbacks module and have I18n.fallbacks configured.
  • [Changed] i18n lint:translations and i18n lint:scripts now support globs in their ignore option.
  • [Removed] Previous versions allowed bare keys in lint's :ignore rule. This is no longer supported; instead, use *.key.
  • [Removed] Remove i18n check; use i18n lint:translations instead.
  • [Fixed] Return the number of missing translations as the exit code when running i18n lint:scripts.
  • [Changed] Plugin configuration moved from top-level keys to a pipeline: array in the config file. Each entry requires a plugin: key identifying the plugin and an enabled: key. Plugin-specific options are defined inline in the same stage object.
  • [Changed] I18nJS::Plugin.key is now a class method returning a String. Previously it was an instance method called config_key that returned a Symbol.
  • [Changed] I18nJS::Plugin#initialize now accepts plugin_config: and main_config: instead of a single config: argument.
  • [Changed] I18nJS::Plugin#config now returns only the plugin's own configuration slice instead of the full main config.
  • [Changed] I18nJS.initialize_plugins! now returns the list of active plugin instances. The I18nJS.plugins accessor has been removed.
  • [Changed] I18nJS::Schema.root_keys is now a frozen Array. Plugins no longer need to register a root key in their setup method.
  • [Changed] Schema validation paths in validate_schema are now relative to the plugin's own config root. Remove the leading config_key segment from all paths passed to schema.* helpers.
  • [Removed] The check: root key is no longer recognised by the schema validator. Remove it from your config file.
  • [Added] A single plugin class can now appear multiple times in the pipeline with different configurations, each running as an independent instance.
  • [Changed] Export translations in parallel. To enable parallel mode, your output file definition must include the :locale placeholder.

... (truncated)

Commits

Updates shakapacker from 9.5.0 to 10.3.1

Release notes

Sourced from shakapacker's releases.

v10.3.0

Added

Fixed

  • Fixed implicit SWC defaults for existing webpack/Babel apps without swc-loader. [PR #1206](shakacode/shakapacker#1206) by justin808. Webpack apps that omit both javascript_transpiler and the deprecated webpack_loader now fall back to Babel with a warning when Shakapacker's bundled SWC default is active, swc-loader is missing, and Babel is present. Explicit transpiler settings, webpack apps with swc-loader, and Rspack's built-in SWC path keep their existing behavior. Closes #1203.
  • Fixed JavaScript config loading for missing Rails environments to use the production fallback. [PR #1206](shakacode/shakapacker#1206) by justin808. When RAILS_ENV has no matching section in config/shakapacker.yml, the Node package config now merges the production section instead of only bundled defaults, matching Ruby configuration loading and honoring explicit production javascript_transpiler, source_path, dev_server, and related settings for custom environments such as staging.
  • Fixed helper binstubs delegating Node resolution to Ruby exec in unset and empty PATH environments. [PR #1200](shakacode/shakapacker#1200) and [PR #1201](shakacode/shakapacker#1201) by justin808. Restores shell-compatible Node lookup for bin/shakapacker-config and bin/diff-bundler-config after the v10.2.0 Ruby-binstub regression, while keeping friendly missing-Node errors for ENOENT and EACCES.

v10.2.0

Added

  • Added webpack_compile_flags configuration. [PR #1180](shakacode/shakapacker#1180) by justin808. Allows Rails-driven Shakapacker compiles to pass extra webpack/rspack CLI flags, such as --fail-on-warnings or --progress, through bin/shakapacker. Fixes #1175.
  • Added AI analysis prompt generation to the config exporter. [PR #695](shakacode/shakapacker#695), [PR #1184](shakacode/shakapacker#1184) by justin808. When running doctor mode (bin/shakapacker-config --doctor), the exporter now also writes an AI-ANALYSIS-PROMPT.md: a ready-to-paste prompt that guides an AI assistant (ChatGPT, Claude, Gemini, etc.) to review the configuration for migration issues (webpack ↔ rspack), build errors, client/server and development/production optimizations, and best practices. The React on Rails–specific guidance in the generated prompt is included only when React on Rails is detected in the app (via package.json, Gemfile, or Gemfile.lock). This is purely additive; existing exports are unchanged, and a failure to write the prompt file only warns without affecting the exported configs.
  • Added support for sass-loader v17. [PR #1141](shakacode/shakapacker#1141) by fukayatsu. Widened the optional sass-loader peer range to ^13.0.0 || ^14.0.0 || ^15.0.0 || ^16.0.0 || ^17.0.0 in core shakapacker, shakapacker-webpack, and shakapacker-rspack. The Sass rule already selects loadPaths for v16+ and keeps api: "modern", both of which remain valid in v17. Note that sass-loader v17 requires Node.js 22.11.0+ and drops node-sass and the legacy Sass JS API, so apps that opt into v17 must already be on Node 22.12+ (the upper branch of Shakapacker's engines.node range).
  • Added Babel 8 peer dependency support. [PR #1187](shakacode/shakapacker#1187) by justin808. Widened the Babel peer ranges in core shakapacker and the shakapacker-webpack supplemental package to allow Babel 8, and updated the Shakapacker Babel preset to omit options removed in Babel 8 while preserving existing Babel 7 behavior. Repository development pins stay on Babel 7, with added compatibility tests covering Babel 8. Refs #1163.

Changed

  • New installs now default to Rspack instead of webpack. [PR #1150](shakacode/shakapacker#1150) by justin808. bundle exec rake shakapacker:install now scaffolds an Rspack project (config, dependencies, and config/shakapacker.yml) by default. This is a new-install default only: existing applications are unaffected. The Rspack default applies only to brand-new installs — re-running the installer on an app that already has a config/shakapacker.yml keeps that app's current bundler (and installs that bundler's dependencies), so the installer never silently switches an existing project's bundler. To install with webpack, run bundle exec rake shakapacker:install[webpack] or set SHAKAPACKER_ASSETS_BUNDLER=webpack; to change an existing app's bundler, use bundle exec rake shakapacker:switch_bundler.
  • Changed Rspack support to target Rspack v2 only. [PR #1179](shakacode/shakapacker#1179) by justin808. Core, installer, switch-bundler defaults, supplemental package, dummy app, and docs now use @rspack/core, @rspack/cli, @rspack/dev-server, and @rspack/plugin-react-refresh v2 ranges. Rspack installs now also require rspack-manifest-plugin@^5.2.2, and shakapacker-rspack requires css-loader@^7.1.4 for Rspack v2 peer compatibility. The Rspack React Refresh loader now uses the v2 named ReactRefreshRspackPlugin export instead of retaining legacy v1 export-shape fallbacks.

Fixed

  • Fixed helper binstubs and doctor checks for subdirectory JavaScript layouts. [PR #1192](shakacode/shakapacker#1192) by justin808. bin/shakapacker-config and bin/diff-bundler-config now resolve package scripts from a configured client package root before falling back to the Rails root, and shakapacker:doctor now searches package metadata, lockfiles, and installed packages across client/root layouts while reducing false SWC dependency issues for custom hybrid webpack/Rspack setups. Fixes #1170 and #1090.
  • Fixed dev-server passthrough argument validation messages. [PR #1180](shakacode/shakapacker#1180) by justin808. bin/shakapacker-dev-server -- --host ... or --port ... now fails with a clearer Shakapacker message instead of forwarding the separator to the bundler; set dev_server.host and dev_server.port in config/shakapacker.yml instead.
  • Fixed shakapacker:export_bundler_config regression on apps upgraded from older Shakapacker versions. [PR #1127](shakacode/shakapacker#1127) by justin808. The task previously invoked bin/shakapacker-config unconditionally via RbConfig.ruby, which crashed when the file was still the legacy JavaScript binstub (#!/usr/bin/env node) left over from earlier installs. The task now inspects the shebang and exec's the file directly when it points at Node, while keeping the Ruby+RbConfig.ruby path for the current Ruby binstub. Affected users are also nudged to run bundle exec rake shakapacker:binstubs to refresh their helper binstub. Refs #1123.
  • Fixed shakapacker:doctor Sass implementation detection for sass-embedded apps. [PR #1178](shakacode/shakapacker#1178) by justin808. The doctor now accepts either modern Sass implementation package (sass or sass-embedded) when Sass files are present, matching Shakapacker's default modern Sass API instead of incorrectly requiring Dart Sass. New installs also include sass alongside sass-loader. Fixes #1172.
  • Fixed Psych::DisallowedClass boot crash when pnpm-lock.yaml contains a time: section. [PR #1161](shakacode/shakapacker#1161) by justin808. pnpm >= 10.16 (default in pnpm 11) writes publish timestamps into pnpm-lock.yaml that Psych 4+ refuses to safe-load, so the shakapacker.version_checker boot initializer raised Psych::DisallowedClass: Tried to load unspecified class: Time and crashed every Rails boot — even when version checking was disabled. The lockfile is now parsed with YAML.safe_load(..., permitted_classes: [Time, Date]). Fixes #1160.
  • Fixed Rspack dev-server lazy compilation defaults for Rails split dev-server topology. [PR #1179](shakacode/shakapacker#1179) by justin808. Generated Rspack development configs now set top-level lazyCompilation: false while the dev server is running, preventing Rspack CLI dev-server auto-lazy behavior from routing dynamic imports through lazy trigger URLs Rails does not serve. Apps that intentionally use lazy compilation can still set a safe top-level lazyCompilation value in their Rspack config.
  • Fixed Rspack dev-server config loading during static watch builds. [PR #1142](shakacode/shakapacker#1142) by justin808. The Rspack devServer configuration is now gated behind WEBPACK_SERVE=true, matching the webpack development config, so static watch builds (bin/shakapacker --watch) no longer load the dev-server client. The devMiddleware.writeToDisk filter that skips hot-update files is preserved. Fixes #1137.
  • Fixed compiler strategies ignoring the instance config of custom Shakapacker::Instance objects. [PR #1147](shakacode/shakapacker#1147) by justin808. Ports #976 by brunodccarvalho. Strategies now read the instance-specific config and watch both webpack and rspack config directories.

v10.1.0

Added

  • Added supplemental npm packages shakapacker-webpack and shakapacker-rspack. [PR #1096](shakacode/shakapacker#1096), [PR #1133](shakacode/shakapacker#1133) by justin808. Optional packages that lockstep with core and declare the managed-build stack as required peer dependencies (so on npm 7+ a single yarn add shakapacker-webpack auto-installs shakapacker, webpack, webpack-cli, and webpack-assets-manifest; shakapacker-rspack declares shakapacker, @rspack/core, @rspack/cli, and rspack-manifest-plugin). Required peers eliminate the silent duplicate-bundler failure mode that direct dependencies could cause when an app or transitive dep pins a different bundler version. Optional features (transpilers, dev-server, CSS preprocessors, react-refresh) remain as opt-in peerDependencies so SCSS/native-binding bloat isn't forced on every install. The wrappers emit structured warnings (SHAKAPACKER_BUNDLER_MISMATCH, SHAKAPACKER_NO_TRANSPILER) when config.assets_bundler or javascript_transpiler doesn't match the installed peers. pnpm and Yarn PnP users should keep packages imported by app config files as explicit app dependencies (the Rails installer handles this automatically). See the v10.1 migration guide for adoption steps and https://github.com/shakacode/shakapacker/blob/HEAD/docs/dependency-strategy.md for the design rationale and v11 roadmap.
  • Added shakapacker:doctor check for disabled Rspack cache. [PR #1100](shakacode/shakapacker#1100) by justin808. The doctor now inspects the Rspack config file for an explicit cache: false, warns when found (disabling cache causes significantly slower builds), and also flags Rspack v1 installs (where persistent cache is experimental) with a recommendation to upgrade to v2.
  • Added a shakapacker:doctor hint to compiler output. [PR #1100](shakacode/shakapacker#1100) by justin808. The compiler now logs a one-time tip suggesting bundle exec rake shakapacker:doctor after a failed compilation, so healthy build loops stay quiet.

Migration Notes

  • Simplify your package.json by adopting a supplemental package. On npm 7+ (or Yarn 2+ in nodeLinker: node-modules mode), existing apps can drop the explicit managed-build deps from devDependencies and let the supplemental package's required peers be auto-installed:
    • Rspack apps can replace shakapacker + @rspack/core + @rspack/cli + rspack-manifest-plugin with a single shakapacker-rspack. See packages/shakapacker-rspack/README.md §"Simplifying an existing rspack install" for the before/after.
    • Webpack apps can replace shakapacker + webpack + webpack-cli + webpack-assets-manifest with a single shakapacker-webpack. See packages/shakapacker-webpack/README.md §"Simplifying an existing webpack install" for the before/after.
    • Optional peers (transpilers, webpack-dev-server, CSS preprocessors, react-refresh) stay only if your app uses those features.
    • Adoption is opt-in: leaving your package.json untouched on v10.1 also continues to work.

... (truncated)

Changelog

Sourced from shakapacker's changelog.

[v10.3.1] - August 3, 2026

Fixed

  • Fixed 502 responses for proxied dev server assets under rack-proxy v1. [PR #1222](shakacode/shakapacker#1222) by jcbpl. Fixes #1220.
  • Fixed dev-server liveness checks treating refused macOS 27 connections as running. The Ruby probe now verifies the connected socket's SO_ERROR result before proxying asset requests, avoiding false-positive dev-server detection and resulting 502 responses. [PR #1225](shakacode/shakapacker#1225) by justin808. Fixes #1224.
  • Fixed webpack Babel, SWC, and esbuild rules skipping explicitly included .cjs files. [PR #1219](shakacode/shakapacker#1219) by oiahoon. Fixes #1218.
  • Added a shakapacker:doctor warning for Rspack React Refresh v2 configs that still use the v1 default-export constructor pattern. [PR #1207](shakacode/shakapacker#1207) by justin808. Existing configs with const ReactRefreshPlugin = require("@rspack/plugin-react-refresh") followed by new ReactRefreshPlugin() can fail after upgrading to @rspack/plugin-react-refresh v2 with ReactRefreshPlugin is not a constructor; Doctor now points to the affected JS/TS config file and suggests the named-export/default/module compatibility form. Fixes #1204.
  • Fixed the missing-@babel/core failure to report an actionable install message. [PR #1212](shakacode/shakapacker#1212) by justin808. Babel-transpiled builds whose app lacks @babel/core previously surfaced a raw module-resolution error from the Babel 8 compatibility check; the rule now explains which package to install and how to switch javascript_transpiler instead. Refs #1163.

Documentation

  • Documented the required css-loader@^7.1.4 in the v10 Rspack upgrade instructions. [PR #1211](shakacode/shakapacker#1211) by justin808. The v10 upgrade guide's copy-paste Rspack v2 commands omitted css-loader, so apps following them could upgrade into an unsatisfied peer dependency.

[v10.3.0] - July 5, 2026

Added

Fixed

  • Fixed implicit SWC defaults for existing webpack/Babel apps without swc-loader. [PR #1206](shakacode/shakapacker#1206) by justin808. Webpack apps that omit both javascript_transpiler and the deprecated webpack_loader now fall back to Babel with a warning when Shakapacker's bundled SWC default is active, swc-loader is missing, and Babel is present. Explicit transpiler settings, webpack apps with swc-loader, and Rspack's built-in SWC path keep their existing behavior. Closes #1203.
  • Fixed JavaScript config loading for missing Rails environments to use the production fallback. [PR #1206](shakacode/shakapacker#1206) by justin808. When RAILS_ENV has no matching section in config/shakapacker.yml, the Node package config now merges the production section instead of only bundled defaults, matching Ruby configuration loading and honoring explicit production javascript_transpiler, source_path, dev_server, and related settings for custom environments such as staging.
  • Fixed helper binstubs delegating Node resolution to Ruby exec in unset and empty PATH environments. [PR #1200](shakacode/shakapacker#1200) and [PR #1201](shakacode/shakapacker#1201) by justin808. Restores shell-compatible Node lookup for bin/shakapacker-config and bin/diff-bundler-config after the v10.2.0 Ruby-binstub regression, while keeping friendly missing-Node errors for ENOENT and EACCES.

[v10.2.0] - July 3, 2026

Added

  • Added webpack_compile_flags configuration. [PR #1180](shakacode/shakapacker#1180) by justin808. Allows Rails-driven Shakapacker compiles to pass extra webpack/rspack CLI flags, such as --fail-on-warnings or --progress, through bin/shakapacker. Fixes #1175.
  • Added AI analysis prompt generation to the config exporter. [PR #695](shakacode/shakapacker#695), [PR #1184](shakacode/shakapacker#1184) by justin808. When running doctor mode (bin/shakapacker-config --doctor), the exporter now also writes an AI-ANALYSIS-PROMPT.md: a ready-to-paste prompt that guides an AI assistant (ChatGPT, Claude, Gemini, etc.) to review the configuration for migration issues (webpack ↔ rspack), build errors, client/server and development/production optimizations, and best practices. The React on Rails–specific guidance in the generated prompt is included only when React on Rails is detected in the app (via package.json, Gemfile, or Gemfile.lock). This is purely additive; existing exports are unchanged, and a failure to write the prompt file only warns without affecting the exported configs.
  • Added support for sass-loader v17. [PR #1141](shakacode/shakapacker#1141) by fukayatsu. Widened the optional sass-loader peer range to ^13.0.0 || ^14.0.0 || ^15.0.0 || ^16.0.0 || ^17.0.0 in core shakapacker, shakapacker-webpack, and shakapacker-rspack. The Sass rule already selects loadPaths for v16+ and keeps api: "modern", both of which remain valid in v17. Note that sass-loader v17 requires Node.js 22.11.0+ and drops node-sass and the legacy Sass JS API, so apps that opt into v17 must already be on Node 22.12+ (the upper branch of Shakapacker's engines.node range).
  • Added Babel 8 peer dependency support. [PR #1187](shakacode/shakapacker#1187) by justin808. Widened the Babel peer ranges in core shakapacker and the shakapacker-webpack supplemental package to allow Babel 8, and updated the Shakapacker Babel preset to omit options removed in Babel 8 while preserving existing Babel 7 behavior. Repository development pins stay on Babel 7, with added compatibility tests covering Babel 8. Refs #1163.

Changed

  • New installs now default to Rspack instead of webpack. [PR #1150](shakacode/shakapacker#1150) by justin808. bundle exec rake shakapacker:install now scaffolds an Rspack project (config, dependencies, and config/shakapacker.yml) by default. This is a new-install default only: existing applications are unaffected. The Rspack default applies only to brand-new installs — re-running the installer on an app that already has a config/shakapacker.yml keeps that app's current bundler (and installs that bundler's dependencies), so the installer never silently switches an existing project's bundler. To install with webpack, run bundle exec rake shakapacker:install[webpack] or set SHAKAPACKER_ASSETS_BUNDLER=webpack; to change an existing app's bundler, use bundle exec rake shakapacker:switch_bundler.
  • Changed Rspack support to target Rspack v2 only. [PR #1179](shakacode/shakapacker#1179) by justin808. Core, installer, switch-bundler defaults, supplemental package, dummy app, and docs now use @rspack/core, @rspack/cli, @rspack/dev-server, and @rspack/plugin-react-refresh v2 ranges. Rspack installs now also require rspack-manifest-plugin@^5.2.2, and shakapacker-rspack requires css-loader@^7.1.4 for Rspack v2 peer compatibility. The Rspack React Refresh loader now uses the v2 named ReactRefreshRspackPlugin export instead of retaining legacy v1 export-shape fallbacks.

Fixed

  • Fixed helper binstubs and doctor checks for subdirectory JavaScript layouts. [PR #1192](shakacode/shakapacker#1192) by justin808. bin/shakapacker-config and bin/diff-bundler-config now resolve package scripts from a configured client package root before falling back to the Rails root, and shakapacker:doctor now searches package metadata, lockfiles, and installed packages across client/root layouts while reducing false SWC dependency issues for custom hybrid webpack/Rspack setups. Fixes #1170 and #1090.
  • Fixed dev-server passthrough argument validation messages. [PR #1180](shakacode/shakapacker#1180) by justin808. bin/shakapacker-dev-server -- --host ... or --port ... now fails with a clearer Shakapacker message instead of forwarding the separator to the bundler; set dev_server.host and dev_server.port in config/shakapacker.yml instead.
  • Fixed shakapacker:export_bundler_config regression on apps upgraded from older Shakapacker versions. [PR #1127](shakacode/shakapacker#1127) by justin808. The task previously invoked bin/shakapacker-config unconditionally via RbConfig.ruby, which crashed when the file was still the legacy JavaScript binstub (#!/usr/bin/env node) left over from earlier installs. The task now inspects the shebang and exec's the file directly when it points at Node, while keeping the Ruby+RbConfig.ruby path for the current Ruby binstub. Affected users are also nudged to run bundle exec rake shakapacker:binstubs to refresh their helper binstub. Refs #1123.
  • Fixed shakapacker:doctor Sass implementation detection for sass-embedded apps. [PR #1178](shakacode/shakapacker#1178) by justin808. The doctor now accepts either modern Sass implementation package (sass or sass-embedded) when Sass files are present, matching Shakapacker's default modern Sass API instead of incorrectly requiring Dart Sass. New installs also include sass alongside sass-loader. Fixes #1172.
  • Fixed Psych::DisallowedClass boot crash when pnpm-lock.yaml contains a time: section. [PR #1161](shakacode/shakapacker#1161) by justin808. pnpm >= 10.16 (default in pnpm 11) writes publish timestamps into pnpm-lock.yaml that Psych 4+ refuses to safe-load, so the shakapacker.version_checker boot initializer raised Psych::DisallowedClass: Tried to load unspecified class: Time and crashed every Rails boot — even when version checking was disabled. The lockfile is now parsed with YAML.safe_load(..., permitted_classes: [Time, Date]). Fixes #1160.
  • Fixed Rspack dev-server lazy compilation defaults for Rails split dev-server topology. [PR #1179](shakacode/shakapacker#1179) by justin808. Generated Rspack development configs now set top-level lazyCompilation: false while the dev server is running, preventing Rspack CLI dev-server auto-lazy behavior from routing dynamic imports through lazy trigger URLs Rails does not serve. Apps that intentionally use lazy compilation can still set a safe top-level lazyCompilation value in their Rspack config.
  • Fixed Rspack dev-server config loading during static watch builds. [PR #1142](shakacode/shakapacker#1142) by justin808. The Rspack devServer configuration is now gated behind WEBPACK_SERVE=true, matching the webpack development config, so static watch builds (bin/shakapacker --watch) no longer load the dev-server client. The devMiddleware.writeToDisk filter that skips hot-update files is preserved. Fixes #1137.
  • Fixed compiler strategies ignoring the instance config of custom Shakapacker::Instance objects. [PR #1147](shakacode/shakapacker#1147) by justin808. Ports #976 by brunodccarvalho. Strategies now read the instance-specific config and watch both webpack and rspack config directories.

... (truncated)

Commits

Updates rspec-rails from 6.1.5 to 8.0.4

Changelog

Sourced from rspec-rails's changelog.

8.0.4 / 2026-03-10

Full Changelog

Released to relax version constraint for rspec to allow 4.0.0.beta1.

8.0.3 / 2026-02-17

Full Changelog

Bug Fixes:

  • Fix insertion order of controller prefix in the view lookup_context. (Stephen Nelson, #2749)
  • Ensure rails stats looks for specs using application root rather than working directory. (Marvin Tangpos, #2879)

8.0.2 / 2025-08-12

Full Changelog

Bug Fixes:

8.0.1 / 2025-06-19

Full Changelog

Bug Fixes:

  • Make the have_been_performed / have_been_enqueued return false for supports_block_expectations? as they don't supporting block expectations. (Sam Kidman, rspec/rspec-rails#2851)

8.0.0 / 2025-04-30

Full Changelog

Enhancements:

  • Add Rails 8 authentication generator support. (Jerome Dalbert, rspec/rspec-rails#2811)
  • Improve install generator comment for ActiveRecord::Migration.maintain_test_schema! rspec/rspec-rails#2832
  • Add support for served_by in system specs. (Sam Giffney, rspec/rspec-rails#2841)

Breaking Changes:

  • Minimum supported Rails version is 7.2.0

7.1.1 / 2025-02-06

Full Changelog

Bug Fixes:

... (truncated)

Commits

Updates shoulda-matchers from 7.0.1 to 8.0.1

Release notes

Sourced from shoulda-matchers's releases.

v8.0.1

What's Changed

Full Changelog: thoughtbot/shoulda-matchers@v8.0.0...v8.0.1

v8.0.0

8.0.0 - 2026-06-12

Backward-incompatible changes

Features

Bug fixes

  • Prevent ActiveRecord constant leak in uniqueness matcher by

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Aug 18, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 18, 2026 10:17
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Aug 18, 2026
@dependabot dependabot Bot changed the title Bump the major-updates group with 8 updates Bump the major-updates group across 1 directory with 8 updates Aug 18, 2026
@dependabot
dependabot Bot force-pushed the dependabot/bundler/major-updates-0347291dba branch from be24941 to 67ac12e Compare August 18, 2026 11:36
@aaccensi aaccensi added the do-not-merge Informational PR. Do not merge directly label Aug 18, 2026
@dependabot
dependabot Bot force-pushed the dependabot/bundler/major-updates-0347291dba branch 3 times, most recently from dd862cb to 263485b Compare August 18, 2026 15:10
Bumps the major-updates group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [discard](https://github.com/jhawthorn/discard) | `1.4.0` | `2.0.0` |
| [haml](https://github.com/haml/haml) | `5.2.2` | `7.3.1` |
| [i18n-js](https://github.com/fnando/i18n-js) | `3.9.2` | `4.2.4` |
| [shakapacker](https://github.com/shakacode/shakapacker) | `9.5.0` | `10.3.1` |
| [rspec-rails](https://github.com/rspec/rspec-rails) | `6.1.5` | `8.0.4` |
| [shoulda-matchers](https://github.com/thoughtbot/shoulda-matchers) | `7.0.1` | `8.0.1` |
| [simplecov](https://github.com/simplecov-ruby/simplecov) | `0.22.0` | `1.1.1` |
| [puma](https://github.com/puma/puma) | `7.2.1` | `8.0.2` |



Updates `discard` from 1.4.0 to 2.0.0
- [Changelog](https://github.com/jhawthorn/discard/blob/master/CHANGELOG.md)
- [Commits](jhawthorn/discard@v1.4.0...v2.0.0)

Updates `haml` from 5.2.2 to 7.3.1
- [Release notes](https://github.com/haml/haml/releases)
- [Changelog](https://github.com/haml/haml/blob/main/CHANGELOG.md)
- [Commits](haml/haml@v5.2.2...v7.3.1)

Updates `i18n-js` from 3.9.2 to 4.2.4
- [Changelog](https://github.com/fnando/i18n-js/blob/main/CHANGELOG.md)
- [Commits](fnando/i18n-js@v3.9.2...v4.2.4)

Updates `shakapacker` from 9.5.0 to 10.3.1
- [Release notes](https://github.com/shakacode/shakapacker/releases)
- [Changelog](https://github.com/shakacode/shakapacker/blob/main/CHANGELOG.md)
- [Commits](shakacode/shakapacker@v9.5.0...v10.3.1)

Updates `rspec-rails` from 6.1.5 to 8.0.4
- [Changelog](https://github.com/rspec/rspec-rails/blob/main/Changelog.md)
- [Commits](rspec/rspec-rails@v6.1.5...v8.0.4)

Updates `shoulda-matchers` from 7.0.1 to 8.0.1
- [Release notes](https://github.com/thoughtbot/shoulda-matchers/releases)
- [Changelog](https://github.com/thoughtbot/shoulda-matchers/blob/main/CHANGELOG.md)
- [Commits](thoughtbot/shoulda-matchers@v7.0.1...v8.0.1)

Updates `simplecov` from 0.22.0 to 1.1.1
- [Release notes](https://github.com/simplecov-ruby/simplecov/releases)
- [Changelog](https://github.com/simplecov-ruby/simplecov/blob/main/CHANGELOG.md)
- [Commits](simplecov-ruby/simplecov@v0.22.0...v1.1.1)

Updates `puma` from 7.2.1 to 8.0.2
- [Release notes](https://github.com/puma/puma/releases)
- [Changelog](https://github.com/puma/puma/blob/main/History.md)
- [Commits](puma/puma@v7.2.1...v8.0.2)

---
updated-dependencies:
- dependency-name: discard
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: haml
  dependency-version: 7.3.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: i18n-js
  dependency-version: 4.2.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: puma
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: rspec-rails
  dependency-version: 8.0.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: shakapacker
  dependency-version: 10.3.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: shoulda-matchers
  dependency-version: 8.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: simplecov
  dependency-version: 1.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: major-updates
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/major-updates-0347291dba branch from 263485b to a27669b Compare August 18, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file do-not-merge Informational PR. Do not merge directly ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant