Skip to content

Bump the bundler group with 5 updates - #27

Merged
dduugg merged 1 commit into
mainfrom
dependabot/bundler/bundler-01f7ee7508
Sep 29, 2026
Merged

dduugg merged 1 commit into
mainfrom
dependabot/bundler/bundler-01f7ee7508

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the bundler group with 5 updates:

Package From To
rubocop 1.90.0 1.91.0
rubocop-sorbet 0.15.0 0.16.0
sorbet 0.6.13454 0.6.13506
mcp 1.4.0 1.6.0
sorbet-runtime 0.6.13454 0.6.13506

Updates rubocop from 1.90.0 to 1.91.0

Release notes

Sourced from rubocop's releases.

RuboCop v1.91.0

New features

  • #15631: Add a preview channel for unstable behavior. ([@​bbatsov][])
  • #15627: Add a SARIF formatter. ([@​bbatsov][])
  • #15686: Add AllCops: FailLevel, the configuration equivalent of --fail-level. ([@​bbatsov][])
  • #15650: Add AllowedDirectives option to Style/DisableCopsWithinSourceCodeDirective, exempting directive kinds such as generated rubocop:todo comments. ([@​bbatsov][])
  • #15629: Add --changed to inspect only the files git says changed. ([@​bbatsov][])
  • #15628: Add --diff to preview autocorrection without writing files. ([@​bbatsov][])
  • #15615: Add new Lint/MisplacedMagicComment cop to flag magic comments in positions where Ruby ignores them. ([@​bbatsov][])
  • #15600: Add the rubocop:enable-next directive to re-enable cops for the next statement only. ([@​bbatsov][])
  • #15600: Add the rubocop:next directive, combining push-style +/- arguments with disable-next's statement scope. ([@​bbatsov][])
  • #15363: Let a cop's entry in the default configuration carry a Preview section with the defaults it is expected to adopt in the next major release, applied under Preview. ([@​bbatsov][])

Bug fixes

  • #15349: Fix a false positive for Style/RedundantRegexpCharacterClass with \8/\9. ([@​bbatsov][])
  • #15646: Fix an error for Layout/ElseAlignment when else is used with rescue in a class, module, or singleton class body. ([@​viralpraxis][])
  • #15613: Fix an error for Layout/HashAlignment when a hash value starts on the line below its key. ([@​viralpraxis][])
  • #15623: Fix an error for Layout/HashAlignment when the first pair of a hash omits its value, and an incorrect autocorrection when a later pair does. ([@​viralpraxis][])
  • #15602: Fix an error for Layout/IndentationWidth on under-indented code with tab indentation. ([@​Starlexxx][])
  • #15672: Fix an error for Lint/RedundantCopDisableDirective when a file contains more than one rubocop:push/rubocop:pop pair. ([@​koic][])
  • #15625: Fix an error for Style/AccessModifierDeclarations when a body repeats the same access modifier. ([@​viralpraxis][])
  • #15603: Fix an error for Style/AccessModifierDeclarations with EnforcedStyle: inline when an access modifier is the body of an if without an else branch. ([@​viralpraxis][])
  • #15604: Fix an error for Style/ConstantVisibility when a visibility declaration splats anything other than an array literal, e.g. private_constant(*constants(false)). ([@​viralpraxis][])
  • #15647: Fix an error for Style/DocumentationMethod when an inline module_function/ruby2_keywords def is preceded by another argument. ([@​viralpraxis][])
  • #15680: Fix an error for Style/EndlessMethod when a method definition is nested inside another method definition. ([@​viralpraxis][])
  • #15674: Fix an error for Style/FloatDivision when using EnforcedStyle: fdiv and one operand of a float division is itself a parenthesized float division. ([@​viralpraxis][])
  • #15624: Fix an error for Style/HashLookupMethod when the looked-up key is itself a hash lookup. ([@​viralpraxis][])
  • #15642: Fix an error for Style/HashSyntax when hash rockets are enforced and a hash value repeats its key. ([@​viralpraxis][])
  • #15634: Fix an incorrect autocorrect for Lint/LiteralAsCondition when the other operand is a parenthesized return. ([@​Starlexxx][])
  • #15648: Fix an incorrect autocorrect for Lint/ParenthesesAsGroupedExpression when the parentheses contain and, or, not, or a modifier expression. ([@​Starlexxx][])
  • #15612: Fix an incorrect autocorrect for Naming/BlockForwarding with Style/MethodDefParentheses. ([@​Starlexxx][])
  • #15680: Fix an incorrect autocorrect for Style/EndlessMethod when using EnforcedStyle: require_always and the method body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15669: Fix an incorrect autocorrect for Style/FloatDivision when using EnforcedStyle: fdiv and the divisor is a method call with parenthesized arguments. ([@​viralpraxis][])
  • #15678: Fix an incorrect autocorrect for Style/For when using EnforcedStyle: for and the block body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15645: Fix an incorrect autocorrect for Style/GuardClause with Style/MissingElse. ([@​Starlexxx][])
  • #15668: Fix an incorrect autocorrect for Style/MethodCallWithArgsParentheses when EnforcedStyle: omit_parentheses is used together with Style/TrailingCommaInArguments. ([@​viralpraxis][])
  • #15347: Fix an incorrect autocorrect for Style/NestedModifier. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/NonNilCheck. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/Not with a flip-flop or assignment. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantDoubleSplatHashBraces with a braced merge argument. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantParentheses around and/or. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantRegexpConstructor with %r{} delimiters. ([@​bbatsov][])
  • #15614: Fix an infinite loop between Layout/ArgumentAlignment and Layout/HashAlignment with separator style. ([@​Starlexxx][])
  • #15599: Fix an infinite loop error for Layout/CommentIndentation when many comment blocks with the same indentation are separated by empty lines. ([@​Starlexxx][])
  • #15597: Fix an infinite loop error for Layout/EmptyLinesAfterModuleInclusion when a module inclusion is directly before rescue. ([@​Starlexxx][])
  • #15617: Fix an infinite loop between Layout/ExtraSpacing with ForceEqualSignAlignment and Layout/SpaceAroundOperators. ([@​Starlexxx][])
  • #15638: Fix an infinite loop error for Layout/FirstArrayElementIndentation with Layout/ArrayAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])
  • #15639: Fix an infinite loop error for Layout/FirstParameterIndentation with Layout/ParameterAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])

... (truncated)

Changelog

Sourced from rubocop's changelog.

1.91.0 (2026-09-10)

New features

  • #15631: Add a preview channel for unstable behavior. ([@​bbatsov][])
  • #15627: Add a SARIF formatter. ([@​bbatsov][])
  • #15686: Add AllCops: FailLevel, the configuration equivalent of --fail-level. ([@​bbatsov][])
  • #15650: Add AllowedDirectives option to Style/DisableCopsWithinSourceCodeDirective, exempting directive kinds such as generated rubocop:todo comments. ([@​bbatsov][])
  • #15629: Add --changed to inspect only the files git says changed. ([@​bbatsov][])
  • #15628: Add --diff to preview autocorrection without writing files. ([@​bbatsov][])
  • #15615: Add new Lint/MisplacedMagicComment cop to flag magic comments in positions where Ruby ignores them. ([@​bbatsov][])
  • #15600: Add the rubocop:enable-next directive to re-enable cops for the next statement only. ([@​bbatsov][])
  • #15600: Add the rubocop:next directive, combining push-style +/- arguments with disable-next's statement scope. ([@​bbatsov][])
  • #15363: Let a cop's entry in the default configuration carry a Preview section with the defaults it is expected to adopt in the next major release, applied under Preview. ([@​bbatsov][])

Bug fixes

  • #15349: Fix a false positive for Style/RedundantRegexpCharacterClass with \8/\9. ([@​bbatsov][])
  • #15646: Fix an error for Layout/ElseAlignment when else is used with rescue in a class, module, or singleton class body. ([@​viralpraxis][])
  • #15613: Fix an error for Layout/HashAlignment when a hash value starts on the line below its key. ([@​viralpraxis][])
  • #15623: Fix an error for Layout/HashAlignment when the first pair of a hash omits its value, and an incorrect autocorrection when a later pair does. ([@​viralpraxis][])
  • #15602: Fix an error for Layout/IndentationWidth on under-indented code with tab indentation. ([@​Starlexxx][])
  • #15672: Fix an error for Lint/RedundantCopDisableDirective when a file contains more than one rubocop:push/rubocop:pop pair. ([@​koic][])
  • #15625: Fix an error for Style/AccessModifierDeclarations when a body repeats the same access modifier. ([@​viralpraxis][])
  • #15603: Fix an error for Style/AccessModifierDeclarations with EnforcedStyle: inline when an access modifier is the body of an if without an else branch. ([@​viralpraxis][])
  • #15604: Fix an error for Style/ConstantVisibility when a visibility declaration splats anything other than an array literal, e.g. private_constant(*constants(false)). ([@​viralpraxis][])
  • #15647: Fix an error for Style/DocumentationMethod when an inline module_function/ruby2_keywords def is preceded by another argument. ([@​viralpraxis][])
  • #15680: Fix an error for Style/EndlessMethod when a method definition is nested inside another method definition. ([@​viralpraxis][])
  • #15674: Fix an error for Style/FloatDivision when using EnforcedStyle: fdiv and one operand of a float division is itself a parenthesized float division. ([@​viralpraxis][])
  • #15624: Fix an error for Style/HashLookupMethod when the looked-up key is itself a hash lookup. ([@​viralpraxis][])
  • #15642: Fix an error for Style/HashSyntax when hash rockets are enforced and a hash value repeats its key. ([@​viralpraxis][])
  • #15634: Fix an incorrect autocorrect for Lint/LiteralAsCondition when the other operand is a parenthesized return. ([@​Starlexxx][])
  • #15648: Fix an incorrect autocorrect for Lint/ParenthesesAsGroupedExpression when the parentheses contain and, or, not, or a modifier expression. ([@​Starlexxx][])
  • #15612: Fix an incorrect autocorrect for Naming/BlockForwarding with Style/MethodDefParentheses. ([@​Starlexxx][])
  • #15680: Fix an incorrect autocorrect for Style/EndlessMethod when using EnforcedStyle: require_always and the method body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15669: Fix an incorrect autocorrect for Style/FloatDivision when using EnforcedStyle: fdiv and the divisor is a method call with parenthesized arguments. ([@​viralpraxis][])
  • #15678: Fix an incorrect autocorrect for Style/For when using EnforcedStyle: for and the block body has a rescue or ensure clause. ([@​viralpraxis][])
  • #15645: Fix an incorrect autocorrect for Style/GuardClause with Style/MissingElse. ([@​Starlexxx][])
  • #15668: Fix an incorrect autocorrect for Style/MethodCallWithArgsParentheses when EnforcedStyle: omit_parentheses is used together with Style/TrailingCommaInArguments. ([@​viralpraxis][])
  • #15347: Fix an incorrect autocorrect for Style/NestedModifier. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/NonNilCheck. ([@​bbatsov][])
  • #15347: Fix an incorrect autocorrect for Style/Not with a flip-flop or assignment. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantDoubleSplatHashBraces with a braced merge argument. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantParentheses around and/or. ([@​bbatsov][])
  • #15349: Fix an incorrect autocorrect for Style/RedundantRegexpConstructor with %r{} delimiters. ([@​bbatsov][])
  • #15614: Fix an infinite loop between Layout/ArgumentAlignment and Layout/HashAlignment with separator style. ([@​Starlexxx][])
  • #15599: Fix an infinite loop error for Layout/CommentIndentation when many comment blocks with the same indentation are separated by empty lines. ([@​Starlexxx][])
  • #15597: Fix an infinite loop error for Layout/EmptyLinesAfterModuleInclusion when a module inclusion is directly before rescue. ([@​Starlexxx][])
  • #15617: Fix an infinite loop between Layout/ExtraSpacing with ForceEqualSignAlignment and Layout/SpaceAroundOperators. ([@​Starlexxx][])
  • #15638: Fix an infinite loop error for Layout/FirstArrayElementIndentation with Layout/ArrayAlignment when EnforcedStyle: with_fixed_indentation is configured. ([@​RedZapdos123][])

... (truncated)

Commits
  • 6eee0af Cut 1.91
  • ed0572d Update Changelog
  • 3181272 Fix an infinite loop for Style/NumericLiteralPrefix with signed literals
  • b87652a Fix Layout/LineLength SplitStrings loop on trailing-space split point
  • fce7a33 [Fix #15638] Fix first array indentation loop
  • 321bd65 #15347 Fix an incorrect autocorrect for Style/NestedModifier
  • a464cba #15347 Fix incorrect autocorrects for Style/NilComparison with precedence...
  • 3192b70 #15347 Fix an incorrect autocorrect for Style/NonNilCheck
  • f747cab #15347 Fix an incorrect autocorrect for Style/Not with a flip-flop or ass...
  • 3f52020 Add CHANGELOG entry for the preview fail level
  • Additional commits viewable in compare view

Updates rubocop-sorbet from 0.15.0 to 0.16.0

Release notes

Sourced from rubocop-sorbet's releases.

v0.16.0

What's Changed

🛠 Other Changes

Full Changelog: Shopify/rubocop-sorbet@v0.15.0...v0.16.0

Commits
  • a901233 Release v0.16.0
  • 045339d Merge pull request #416 from Shopify/rm-Lint/SelfAssignment
  • e3d8591 Enable AllowRBSInlineAnnotation for Lint/SelfAssignment by default
  • d0141f4 Merge pull request #410 from Shopify/rbs-nested-assertions
  • 70866cd Merge pull request #415 from Shopify/dependabot/github_actions/rubygems/relea...
  • 4bb9c90 Bump rubygems/release-gem from 1.4.0 to 1.4.1
  • 255b396 Autocorrect RBS assertions in arguments
  • See full diff in compare view

Updates sorbet from 0.6.13454 to 0.6.13506

Release notes

Sourced from sorbet's releases.

sorbet 0.6.13505.20260916062055-93ad6f3de

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13505', :group => :development
gem 'sorbet-runtime', '0.6.13505'

sorbet 0.6.13504.20260915163209-38a28a3e8

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13504', :group => :development
gem 'sorbet-runtime', '0.6.13504'

sorbet 0.6.13503.20260915162919-a757543df

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13503', :group => :development
gem 'sorbet-runtime', '0.6.13503'

sorbet 0.6.13502.20260914133809-4951841fa

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13502', :group => :development
gem 'sorbet-runtime', '0.6.13502'

sorbet 0.6.13501.20260914092654-612963259

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13501', :group => :development
gem 'sorbet-runtime', '0.6.13501'

sorbet 0.6.13500.20260914091620-326e2fd00

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13500', :group => :development
gem 'sorbet-runtime', '0.6.13500'

sorbet 0.6.13499.20260912080937-43ff9604b

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13499', :group => :development
gem 'sorbet-runtime', '0.6.13499'

sorbet 0.6.13498.20260911145700-7459ce506

... (truncated)

Commits

Updates mcp from 1.4.0 to 1.6.0

Release notes

Sourced from mcp's releases.

v1.6.0

This release lets an application configure, on the OAuth provider, the requests the flow makes to the authorization server: token_request_params: adds the parameters a server requires beyond the grant itself, and http_client_customizer: adds middleware to the connection the flow uses for discovery, registration, and token requests, behind a guard that refuses a request leaving the origin the flow asked for. The legacy 2025-03-26 discovery path is now taken only when the server publishes no Protected Resource Metadata: a fetch that failed to reach the server, or that answered 5xx or 429, raises Flow::MetadataUnreachableError instead, and the metadata served on that path must name the MCP server's origin as its issuer. The client_credentials and jwt-bearer grants run on that path, and a stored refresh token no longer crashes their providers. MCP::Icon.new now refuses an icon the specification's schema rejects, such as one without src or with sizes given as a String. Three entries under "Changed" reject what earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/HEAD/VERSIONING.md.

Added

  • Add token_request_params: to let a provider add parameters to the token requests it makes (#555)
  • Add http_client_customizer: to let a provider customize the HTTP client the OAuth flow uses (#560)

Changed

  • Validate the issuer of legacy authorization server metadata (#556)
  • Surface unreachable Protected Resource Metadata instead of falling back to legacy discovery (#561)
  • Validate the src and sizes of an icon against the specification (#563)

Fixed

  • Omit the body client_id from token requests that authenticate with HTTP Basic (#548)
  • Preserve the token endpoint's error and error_description in the raised error (#549)
  • Let the client_credentials and jwt-bearer grants run without Protected Resource Metadata (#557)
  • Let providers without a CIMD URL reader refresh their tokens (#559)

v1.5.1

This release keeps the HTTP client working with json 3.0. That release accepts the options of JSON.parse as keywords only, and Faraday's JSON response middleware, through 2.14.3, passes them as a positional Hash, which Ruby 3 no longer converts, so every JSON body the client received failed as an internal error. The client now parses response bodies itself, the way it already handled streamed ones, and no longer registers the middleware. A malformed JSON body delivered whole by an adapter without streaming support now raises RequestHandlerError with error_type: :parse_error, as the streamed path already did.

Fixed

  • Parse HTTP client response bodies without Faraday's JSON middleware, which json 3.0 breaks (#546)

v1.5.0

This release makes the client answer a server's ping with the empty result the specification requires. Earlier clients replied with Method not found over Streamable HTTP and stayed silent over stdio, so a server that checks liveness dropped their long-lived sessions. On the OAuth side, the embedding application can refuse an authorization request through authorization_request_validator, and stored tokens are refreshed only against the authorization server that issued them: when the server named for a session differs, the client reauthorizes instead of refreshing, and the validator sees the newly named server. Tokens stored by earlier releases carry no issuer and keep refreshing.

Added

  • Add authorization_request_validator to let the embedding application refuse an authorization request (#539)

Fixed

  • Answer server-to-client pings in the client (#541)
Changelog

Sourced from mcp's changelog.

[1.6.0] - 2026-09-21

This release lets an application configure, on the OAuth provider, the requests the flow makes to the authorization server: token_request_params: adds the parameters a server requires beyond the grant itself, and http_client_customizer: adds middleware to the connection the flow uses for discovery, registration, and token requests, behind a guard that refuses a request leaving the origin the flow asked for. The legacy 2025-03-26 discovery path is now taken only when the server publishes no Protected Resource Metadata: a fetch that failed to reach the server, or that answered 5xx or 429, raises Flow::MetadataUnreachableError instead, and the metadata served on that path must name the MCP server's origin as its issuer. The client_credentials and jwt-bearer grants run on that path, and a stored refresh token no longer crashes their providers. MCP::Icon.new now refuses an icon the specification's schema rejects, such as one without src or with sizes given as a String. Three entries under "Changed" reject what earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/main/VERSIONING.md.

Added

  • Add token_request_params: to let a provider add parameters to the token requests it makes (#555)
  • Add http_client_customizer: to let a provider customize the HTTP client the OAuth flow uses (#560)

Changed

  • Validate the issuer of legacy authorization server metadata (#556)
  • Surface unreachable Protected Resource Metadata instead of falling back to legacy discovery (#561)
  • Validate the src and sizes of an icon against the specification (#563)

Fixed

  • Omit the body client_id from token requests that authenticate with HTTP Basic (#548)
  • Preserve the token endpoint's error and error_description in the raised error (#549)
  • Let the client_credentials and jwt-bearer grants run without Protected Resource Metadata (#557)
  • Let providers without a CIMD URL reader refresh their tokens (#559)

[1.5.1] - 2026-09-09

This release keeps the HTTP client working with json 3.0. That release accepts the options of JSON.parse as keywords only, and Faraday's JSON response middleware, through 2.14.3, passes them as a positional Hash, which Ruby 3 no longer converts, so every JSON body the client received failed as an internal error. The client now parses response bodies itself, the way it already handled streamed ones, and no longer registers the middleware. A malformed JSON body delivered whole by an adapter without streaming support now raises RequestHandlerError with error_type: :parse_error, as the streamed path already did.

Fixed

  • Parse HTTP client response bodies without Faraday's JSON middleware, which json 3.0 breaks (#546)

[1.5.0] - 2026-09-05

This release makes the client answer a server's ping with the empty result the specification requires. Earlier clients replied with Method not found over Streamable HTTP and stayed silent over stdio,

... (truncated)

Commits
  • 339f0a6 Merge pull request #565 from koic/release_1_6_0
  • ba25682 Release 1.6.0
  • 5ce47b6 Merge pull request #564 from koic/describe_connect_as_lifecycle_negotiation
  • 7b73bc7 [Doc] Describe connect across both protocol lifecycles
  • 538a364 Merge pull request #563 from koic/validate_icon_src_and_sizes
  • 66b2efa Merge pull request #561 from koic/propagate_network_errors_from_protected_res...
  • 8173a38 Validate the src and sizes of an icon against the specification
  • 5f429f3 Merge pull request #560 from koic/let_a_provider_customize_the_oauth_http_client
  • e1105c7 Merge pull request #559 from koic/let_providers_without_a_cimd_url_refresh
  • 5081cc5 Surface unreachable Protected Resource Metadata instead of falling back to le...
  • Additional commits viewable in compare view

Updates sorbet-runtime from 0.6.13454 to 0.6.13506

Release notes

Sourced from sorbet-runtime's releases.

sorbet 0.6.13505.20260916062055-93ad6f3de

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13505', :group => :development
gem 'sorbet-runtime', '0.6.13505'

sorbet 0.6.13504.20260915163209-38a28a3e8

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13504', :group => :development
gem 'sorbet-runtime', '0.6.13504'

sorbet 0.6.13503.20260915162919-a757543df

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13503', :group => :development
gem 'sorbet-runtime', '0.6.13503'

sorbet 0.6.13502.20260914133809-4951841fa

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13502', :group => :development
gem 'sorbet-runtime', '0.6.13502'

sorbet 0.6.13501.20260914092654-612963259

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13501', :group => :development
gem 'sorbet-runtime', '0.6.13501'

sorbet 0.6.13500.20260914091620-326e2fd00

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13500', :group => :development
gem 'sorbet-runtime', '0.6.13500'

sorbet 0.6.13499.20260912080937-43ff9604b

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13499', :group => :development
gem 'sorbet-runtime', '0.6.13499'

sorbet 0.6.13498.20260911145700-7459ce506

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the bundler group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [rubocop](https://github.com/rubocop/rubocop) | `1.90.0` | `1.91.0` |
| [rubocop-sorbet](https://github.com/shopify/rubocop-sorbet) | `0.15.0` | `0.16.0` |
| [sorbet](https://github.com/sorbet/sorbet) | `0.6.13454` | `0.6.13506` |
| [mcp](https://github.com/modelcontextprotocol/ruby-sdk) | `1.4.0` | `1.6.0` |
| [sorbet-runtime](https://github.com/sorbet/sorbet) | `0.6.13454` | `0.6.13506` |


Updates `rubocop` from 1.90.0 to 1.91.0
- [Release notes](https://github.com/rubocop/rubocop/releases)
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md)
- [Commits](rubocop/rubocop@v1.90.0...v1.91.0)

Updates `rubocop-sorbet` from 0.15.0 to 0.16.0
- [Release notes](https://github.com/shopify/rubocop-sorbet/releases)
- [Commits](Shopify/rubocop-sorbet@v0.15.0...v0.16.0)

Updates `sorbet` from 0.6.13454 to 0.6.13506
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

Updates `mcp` from 1.4.0 to 1.6.0
- [Release notes](https://github.com/modelcontextprotocol/ruby-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/ruby-sdk/blob/main/CHANGELOG.md)
- [Commits](modelcontextprotocol/ruby-sdk@v1.4.0...v1.6.0)

Updates `sorbet-runtime` from 0.6.13454 to 0.6.13506
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

---
updated-dependencies:
- dependency-name: rubocop
  dependency-version: 1.91.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: rubocop-sorbet
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: sorbet
  dependency-version: 0.6.13506
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler
- dependency-name: mcp
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler
- dependency-name: sorbet-runtime
  dependency-version: 0.6.13506
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 29, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 29, 2026 20:59
@dduugg
dduugg merged commit 3f6163c into main Sep 29, 2026
8 checks passed
@dduugg
dduugg deleted the dependabot/bundler/bundler-01f7ee7508 branch September 29, 2026 21:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant