🚨 [security] Update devise 5.0.3 → 5.0.4 (patch)#1893
Merged
Conversation
danidoni
approved these changes
May 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ devise (5.0.3 → 5.0.4) · Repo · Changelog
Security Advisories 🚨
🚨 Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
Commits
See the full diff on Github. The new version differs by 7 commits:
Release v5.0.4 with sec fix for timeoutableMerge commit from forkAdd GHSA link to the v5.0.3 sec fix changelog entry [ci skip]Update links to https [ci skip]Bundle updateCleanup old Rails.version check for db migration pathFix Gemfile for Rails 7.2, incorrectly testing against 7.1Release Notes
4.1.2
4.1.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 24 commits:
Bump version to v4.1.2 (#529)Update dtoa to version from Ruby 4.0 (#528)Merge pull request #526 from ruby/dependabot/github_actions/step-security/harden-runner-2.17.0Bump step-security/harden-runner from 2.16.1 to 2.17.0Fix unary minus on unsigned type warning (#525)BigMath.exp overflow/underflow check (#523)Revert "Add a workaround for slow BigDecimal#to_f when it has large N_significant_digits (#514)" (#522)Use '0'+n for converting single digit to char (#521)Merge pull request #517 from ruby/dependabot/github_actions/rubygems/release-gem-1.2.0Merge pull request #518 from ruby/dependabot/github_actions/step-security/harden-runner-2.16.1Fix calloc-transposed-args warning (#520)Optimize BigDecimal#to_s (#519)Bump step-security/harden-runner from 2.16.0 to 2.16.1Bump rubygems/release-gem from 1.1.4 to 1.2.0Bump version to v4.1.1 (#516)Add a workaround for slow BigDecimal#to_f when it has large N_significant_digits (#514)tiny grammar fix in README.md (#513)Update to cover change in Bundler (#512)Increase VpMult batch size (#511)Multiplication with 8-decdig batch (#501)Remove unused minitest from Gemfile (#510)Make BigDecimal object embedded (#507)Add changelog for 4.1.0. (#508)Define `test` as the default rake task (#509)Release Notes
1.18.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 29 commits:
Bump version to 1.18.0 (#1208)Colorize KEYWORD_DO_BLOCK (added in head Prism) (#1207)Fix incorrect dash in startup message (#1206)Add --nobanner option to suppress startup banner (#1200)Bump rubygems/release-gem from 1.1.4 to 1.2.0Bump actions/upload-pages-artifact from 4 to 5Bump step-security/harden-runner from 2.16.0 to 2.17.0Highlight the method name in method calls (#1189)Bump actions/configure-pages from 5 to 6Bump actions/deploy-pages from 4 to 5Wait for pager to terminate (#1192)Fix random EPIPE failure in SIGINT restore tests (#1191)Do not open nesting for character literals (#1190)Bump rubygems/release-gem from 1.1.2 to 1.1.4Bump step-security/harden-runner from 2.15.1 to 2.16.0Add startup banner with Ruby logo, version info, and rotating tips (#1183)Use Prism::ParseResult#continuable? if possible (#1184)Fix display_document test fails in tty environment (#1185)Display command description in doc dialog on tab completion (#1180)Fix IRB crash when typing string literal with control/meta sequence (#1182)Bump step-security/harden-runner from 2.15.0 to 2.15.1Make ls command work for BasicObjects (#1177)Bump step-security/harden-runner from 2.14.2 to 2.15.0Ruby / Prism >= 4.1.0 allows trailing comma in method definition (#1178)Suppress error highlight for some incomplete code (#1173)Completely migrate to prism (#1160)Silence default_external warning in tests (#1172)Bump actions/checkout from 6.0.1 to 6.0.2Bump step-security/harden-runner from 2.14.0 to 2.14.2Release Notes
6.0.6 (from changelog)
6.0.5 (from changelog)
6.0.4 (from changelog)
6.0.3 (from changelog)
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 10 commits:
prepped for release- Removed private Assertions#_where as it is no longer used.- Fix using assert_equal/same/nil w/ BasicObject by comparing w/ `nil == exp`. (mtasaka)Branching minitest to version 6.0.5- Raise TypeError if assert_raises is passed anything but modules/classes.- Avoid circular requires in lib/minitest/server_plugin.rb.prepped for release- Fixed refute_predicate to call assert_respond_to w/ include_all:true like assert_predicate does. (jparker)prepped for release- assert_same(nil, value) no longer allowed. Use assert_nil to be explicit. (paddor)Release Notes
13.4.2
13.4.1
13.4.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands