Skip to content

build(deps): bump the bundler-production-dependencies group across 1 directory with 72 updates#148

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/src/email/bundler-production-dependencies-4123159e59
Open

build(deps): bump the bundler-production-dependencies group across 1 directory with 72 updates#148
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/src/email/bundler-production-dependencies-4123159e59

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 20, 2026

Copy link
Copy Markdown

Bumps the bundler-production-dependencies group with 16 updates in the /src/email directory:

Package From To
puma 7.2.0 8.0.1
google-protobuf 4.34.0 4.35.0
opentelemetry-sdk 1.10.0 1.12.0
opentelemetry-common 0.23.0 0.25.0
opentelemetry-logs-sdk 0.4.0 0.6.0
opentelemetry-metrics-sdk 0.12.0 0.14.0
opentelemetry-exporter-otlp 0.31.1 0.34.0
opentelemetry-exporter-otlp-metrics 0.6.1 0.9.0
opentelemetry-exporter-otlp-logs 0.2.2 0.5.0
opentelemetry-instrumentation-all 0.90.1 0.93.0
openfeature-sdk 0.6.4 0.6.5
grpc 1.78.1 1.80.0
mustermann 3.0.4 3.1.1
net-imap 0.6.3 0.6.4
rack 3.2.5 3.2.6
rack-session 2.1.1 2.1.2

Updates puma from 7.2.0 to 8.0.1

Release notes

Sourced from puma's releases.

v8.0.1

  • Bugfixes

    • Fix prune_bundler stripping user-configured BUNDLE_* env vars (e.g. BUNDLE_WITHOUT) on re-exec, which caused workers to crash on boot (#3929)
  • Performance

    • Use blocks for debug logging to avoid creating log messages when debug is disabled (#3920)
  • Docs

    • Fix incorrect hook names in gRPC docs (#3923)
    • Reword v8 upgrade guide IPv6 bullet for clarity (#3928)

v8.0.0 - Into the Arena

Read our Version 8 Upgrade Guide.

  • Features

    • Add env["puma.mark_as_io_bound"] API and max_io_threads config to allow IO-bound requests to exceed the thread pool max, enabling better handling of mixed workloads (#3816, #3894)
    • Add single and cluster DSL hooks for mode-specific configuration (#3621)
    • Add on_force option to shutdown_debug to only dump thread backtraces on forced (non-graceful) shutdown (#3671)
    • Add API to dynamically update min and max thread counts at runtime via update_thread_pool_min_max and ServerPluginControl (#3658)
    • Use SIGPWR for thread backtrace dumps on Linux/JRuby where SIGINFO is unavailable (#3829)
  • Bugfixes

    • Fix phased restart for fork_worker to avoid forking from stale worker 0 when it has been replaced (#3853)
  • Performance

    • JRuby HTTP parser improvements: pre-allocated header keys, perfect hash lookup, reduced memory copies (#3838)
    • Cache downcased header key in str_headers to avoid redundant String#downcase calls, reducing allocations by ~50% per response (#3874)
  • Refactor

    • Collect env processing into dedicated client_env.rb module (#3582)
    • Move event to default configuration (#3872)
  • Docs

    • Add gRPC guide for configuring gRPC lifecycle hooks in clustered mode (#3885)
    • Add 7.0 upgrade guide, move 5.0/6.0 upgrade guides to docs directory (#3900)
    • Correct default values for persistent_timeout and worker_boot_timeout in DSL docs (#3912)
    • Add file descriptor limit warning in test helper for contributors (#3893)
  • Breaking changes

    • Default production bind address changed from 0.0.0.0 to :: (IPv6) when a non-loopback IPv6 interface is available; falls back to 0.0.0.0 if IPv6 is unavailable (#3847)
Changelog

Sourced from puma's changelog.

8.0.1 / 2026-04-27

  • Bugfixes

    • Fix prune_bundler stripping user-configured BUNDLE_* env vars (e.g. BUNDLE_WITHOUT) on re-exec, which caused workers to crash on boot (#3929)
  • Performance

    • Use blocks for debug logging to avoid creating log messages when debug is disabled (#3920)
  • Docs

    • Fix incorrect hook names in gRPC docs (#3923)
    • Reword v8 upgrade guide IPv6 bullet for clarity (#3928)

8.0.0 / 2026-03-27

  • Features

    • Add env["puma.mark_as_io_bound"] API and max_io_threads config to allow IO-bound requests to exceed the thread pool max, enabling better handling of mixed workloads (#3816, #3894)
    • Add single and cluster DSL hooks for mode-specific configuration (#3621)
    • Add on_force option to shutdown_debug to only dump thread backtraces on forced (non-graceful) shutdown (#3671)
    • Add API to dynamically update min and max thread counts at runtime via update_thread_pool_min_max and ServerPluginControl (#3658)
    • Use SIGPWR for thread backtrace dumps on Linux/JRuby where SIGINFO is unavailable (#3829)
  • Bugfixes

    • Fix phased restart for fork_worker to avoid forking from stale worker 0 when it has been replaced (#3853)
  • Performance

    • JRuby HTTP parser improvements: pre-allocated header keys, perfect hash lookup, reduced memory copies (#3838)
    • Cache downcased header key in str_headers to avoid redundant String#downcase calls, reducing allocations by ~50% per response (#3874)
  • Refactor

    • Collect env processing into dedicated client_env.rb module (#3582)
    • Move event to default configuration (#3872)
  • Docs

    • Add gRPC guide for configuring gRPC lifecycle hooks in clustered mode (#3885)
    • Add 7.0 upgrade guide, move 5.0/6.0 upgrade guides to docs directory (#3900)
    • Correct default values for persistent_timeout and worker_boot_timeout in DSL docs (#3912)
    • Add file descriptor limit warning in test helper for contributors (#3893)
  • Breaking changes

    • Default production bind address changed from 0.0.0.0 to :: (IPv6) when a non-loopback IPv6 interface is available; falls back to 0.0.0.0 if IPv6 is unavailable (#3847)
Commits
  • cee7e61 Release v8.0.1 (#3932)
  • f955caf Fix prune_bundler stripping user-configured BUNDLE_* env vars on re-exec (#3929)
  • 97996aa ci: test_error_logger.rb - fix TruffleRuby error (#3930)
  • 03825bc Build(deps): Bump actions/github-script from 8 to 9 (#3925)
  • 053efae Reword v8 upgrade guide ipv6 bullet (#3928)
  • b19f35a Fix incorrect hook names in gRPC docs (#3923)
  • eeabe4b Use blocks for debug logging to avoid creating messages if debug disabled (#3...
  • 08f63d4 Release v8.0.0 (#3914)
  • 7406cc1 Fix IPv4-mapped IPv6 addresses in REMOTE_ADDR and request logs (#3916)
  • e090243 Build(deps): Bump actions/checkout from 4 to 6 (#3915)
  • Additional commits viewable in compare view

Updates google-protobuf from 4.34.0 to 4.35.0

Commits

Updates opentelemetry-sdk from 1.10.0 to 1.12.0

Release notes

Sourced from opentelemetry-sdk's releases.

opentelemetry-sdk 1.12.0

v1.12.0 / 2026-05-12

  • ADDED: Add git tag to source URI in gemspec (#2101)
  • FIXED: Consistent labels for otel.bsp.dropped_spans metric (#2108)

opentelemetry-sdk 1.11.0

v1.11.0 / 2026-04-07

  • ADDED: Min Ruby Version 3.3 (#2070)
Commits

Updates opentelemetry-common from 0.23.0 to 0.25.0

Release notes

Sourced from opentelemetry-common's releases.

opentelemetry-common 0.25.0

v0.25.0 / 2026-05-12

  • ADDED: Add git tag to source URI in gemspec (#2101)

opentelemetry-common 0.24.0

v0.24.0 / 2026-04-07

  • ADDED: Min Ruby Version 3.3 (#2070)
Commits

Updates opentelemetry-logs-sdk from 0.4.0 to 0.6.0

Release notes

Sourced from opentelemetry-logs-sdk's releases.

opentelemetry-logs-sdk 0.6.0

v0.6.0 / 2026-05-12

  • ADDED: Add event_name field to Logs (#2077)
  • ADDED: Add git tag to source URI in gemspec (#2101)

opentelemetry-logs-sdk 0.5.1

v0.5.1 / 2026-04-15

  • FIXED: Move the logs-sdk requires to support "require 'opentelemetry/sdk/logs'" (#1956)

opentelemetry-logs-sdk 0.5.0

v0.5.0 / 2026-04-07

  • ADDED: Min Ruby Version 3.3 (#2070)
Commits

Updates opentelemetry-metrics-sdk from 0.12.0 to 0.14.0

Release notes

Sourced from opentelemetry-metrics-sdk's releases.

opentelemetry-metrics-sdk 0.14.0

v0.14.0 / 2026-05-12

  • BREAKING CHANGE: Use trace_based exemplar filter by default (#2112)
  • ADDED: Use trace_based exemplar filter by default (#2112)
  • ADDED: Add git tag to source URI in gemspec (#2101)
  • FIXED: Return false if it is noop_exemplar_reservoir (#2104)

opentelemetry-metrics-sdk 0.13.1

v0.13.1 / 2026-04-15

  • FIXED: Move the metrics-sdk requires to support "require 'opentelemetry/sdk/metrics'" (#1956)

opentelemetry-metrics-sdk 0.13.0

v0.13.0 / 2026-04-07

  • ADDED: Min Ruby Version 3.3 (#2070)
  • ADDED: Add basic support for metrics exemplar (#1609)
Commits

Updates opentelemetry-exporter-otlp from 0.31.1 to 0.34.0

Release notes

Sourced from opentelemetry-exporter-otlp's releases.

opentelemetry-exporter-otlp 0.34.0

v0.34.0 / 2026-05-12

  • ADDED: Add git tag to source URI in gemspec (#2101)

opentelemetry-exporter-otlp 0.33.0

v0.33.0 / 2026-04-07

  • ADDED: Min Ruby Version 3.3 (#2070)
  • ADDED: Handle HTTP 2XX responses as successful in OTLP exporters (#2044)
  • FIXED: Issue with sending traces to IPv6 endpoints (#1935)

opentelemetry-exporter-otlp 0.32.0

v0.32.0 / 2026-03-10

  • ADDED: Replace cgi with uri for encode and decode (#2028)
Commits

Updates opentelemetry-exporter-otlp-metrics from 0.6.1 to 0.9.0

Release notes

Sourced from opentelemetry-exporter-otlp-metrics's releases.

opentelemetry-exporter-otlp-metrics 0.9.0

v0.9.0 / 2026-05-12

  • ADDED: Add git tag to source URI in gemspec (#2101)

opentelemetry-exporter-otlp-metrics 0.8.0

v0.8.0 / 2026-04-07

  • ADDED: Min Ruby Version 3.3 (#2070)
  • ADDED: Handle HTTP 2XX responses as successful in OTLP exporters (#2044)
  • ADDED: Add basic support for metrics exemplar (#1609)
  • FIXED: Issue with sending traces to IPv6 endpoints (#1935)

opentelemetry-exporter-otlp-metrics 0.7.0

v0.7.0 / 2026-03-10

  • ADDED: Replace cgi with uri for encode and decode (#2028)
Commits

Updates opentelemetry-exporter-otlp-logs from 0.2.2 to 0.5.0

Release notes

Sourced from opentelemetry-exporter-otlp-logs's releases.

opentelemetry-exporter-otlp-logs 0.5.0

v0.5.0 / 2026-05-12

  • ADDED: Add event_name field to Logs (#2077)
  • ADDED: Add git tag to source URI in gemspec (#2101)

opentelemetry-exporter-otlp-logs 0.4.0

v0.4.0 / 2026-04-07

  • ADDED: Min Ruby Version 3.3 (#2070)
  • ADDED: Handle HTTP 2XX responses as successful in OTLP exporters (#2044)
  • FIXED: Issue with sending traces to IPv6 endpoints (#1935)
  • DOCS: Fix exporter-otlp-logs gemspec metadata links (#2060)

opentelemetry-exporter-otlp-logs 0.3.0

v0.3.0 / 2026-03-10

  • ADDED: Replace cgi with uri for encode and decode (#2028)
Commits

Updates opentelemetry-instrumentation-all from 0.90.1 to 0.93.0

Release notes

Sourced from opentelemetry-instrumentation-all's releases.

opentelemetry-instrumentation-all 0.93.0

v0.93.0 / 2026-04-28

  • ADDED: Upgrade opentelemetry-instrumentation-rails to 0.42.0

opentelemetry-instrumentation-all 0.92.0

v0.92.0 / 2026-04-14

  • BREAKING CHANGE: Min Ruby Version 3.3 (#2125)
  • ADDED: Min Ruby Version 3.3 (#2125)
  • ADDED: Add release tag into source code url of gem metadata (#1984)
  • CHANGED: Update transitive dependencies for all instrumentation gems to new versions

opentelemetry-instrumentation-all 0.91.0

v0.91.0 / 2026-03-17

  • ADDED: Upgrade opentelemetry-instrumentation-anthropic to 0.4.0
  • ADDED: Upgrade opentelemetry-instrumentation-dalli to 0.29.2
  • ADDED: Upgrade opentelemetry-instrumentation-ethon to 0.28.0
  • ADDED: Upgrade opentelemetry-instrumentation-excon to 0.28.0
  • ADDED: Upgrade opentelemetry-instrumentation-faraday to 0.32.0
  • ADDED: Upgrade opentelemetry-instrumentation-grape to 0.6.0
  • ADDED: Upgrade opentelemetry-instrumentation-graphql to 0.31.2
  • ADDED: Upgrade opentelemetry-instrumentation-http to 0.29.0
  • ADDED: Upgrade opentelemetry-instrumentation-http_client to 0.28.0
  • ADDED: Upgrade opentelemetry-instrumentation-httpx to 0.7.0
  • ADDED: Upgrade opentelemetry-instrumentation-net_http to 0.28.0
  • ADDED: Upgrade opentelemetry-instrumentation-racecar to 0.6.1
  • ADDED: Upgrade opentelemetry-instrumentation-rack to 0.30.0
  • ADDED: Upgrade opentelemetry-instrumentation-rails to 0.40.0
  • ADDED: Upgrade opentelemetry-instrumentation-restclient to 0.27.0
  • ADDED: Upgrade opentelemetry-instrumentation-sinatra to 0.29.0
  • ADDED: Upgrade opentelemetry-instrumentation-trilogy to 0.67.0
Commits

Updates openfeature-sdk from 0.6.4 to 0.6.5

Release notes

Sourced from openfeature-sdk's releases.

v0.6.5

0.6.5 (2026-03-18)

Features

  • add RBS type signatures with Steep type checking (#251) (506e999)
Changelog

Sourced from openfeature-sdk's changelog.

0.6.5 (2026-03-18)

Features

  • add RBS type signatures with Steep type checking (#251) (506e999)
Commits
  • fa8026f chore(main): release 0.6.5 (#252)
  • 602d972 chore(deps): update codecov/codecov-action action to v5.5.3 (#253)
  • 506e999 feat: add RBS type signatures with Steep type checking (#251)
  • 3f339dc chore(deps): update dependency ruby to v4.0.2 (#250)
  • c9472a4 ci: add Claude Code GitHub Action (#249)
  • 998c06c chore(deps): update marocchino/sticky-pull-request-comment action to v3 (#248)
  • a86856b chore(deps): update dependency ruby to v3.4.9 (#247)
  • cfdf478 chore: remove known providers table from README (#246)
  • f9d5cfa chore: remove Claude plans and prevent future commits (#245)
  • a10e3ba chore(deps): update dependency rspec to "~> 3.13.0" (#244)
  • Additional commits viewable in compare view

Updates bigdecimal from 4.0.1 to 4.1.2

Release notes

Sourced from bigdecimal's releases.

v4.1.2

What's Changed

New Contributors

Full Changelog: ruby/bigdecimal@v4.1.1...v4.1.2

v4.1.1

What's Changed

New Contributors

Full Changelog: ruby/bigdecimal@v4.1.0...v4.1.1

v4.1.0

What's Changed

... (truncated)

Changelog

Sourced from bigdecimal's changelog.

4.1.2

4.1.1

4.1.0

Commits
  • 9160561 Bump version to v4.1.2 (#529)
  • 8050ec7 Update dtoa to version from Ruby 4.0 (#528)
  • f8a02b2 Merge pull request #526 from ruby/dependabot/github_actions/step-security/har...
  • ac9a5cd Bump step-security/harden-runner from 2.16.1 to 2.17.0
  • 6b51b99 Fix unary minus on unsigned type warning (#525)
  • 50b80b1 BigMath.exp overflow/underflow check (#523)
  • fc54487 Revert "Add a workaround for slow BigDecimal#to_f when it has large N_signifi...
  • 72937b7 Use '0'+n for converting single digit to char (#521)
  • 8ac1498 Merge pull request #517 from ruby/dependabot/github_actions/rubygems/release-...
  • 3c89db5 Merge pull request #518 from ruby/dependabot/github_actions/step-security/har...
  • Additional commits viewable in compare view

Updates googleapis-common-protos-types from 1.22.0 to 1.23.0

Release notes

Sourced from googleapis-common-protos-types's releases.

googleapis-common-protos-types: v1.23.0

1.23.0 (2026-05-19)

Features

  • Regenerate protos and support Ruby min_version 3.2 (#412)
Commits
  • 1bd0442 chore(main): release googleapis-common-protos-types 1.23.0 (#419)
  • a869146 chore(main): release google-apps-script-type 1.8.0 (#414)
  • 1b1f527 chore(main): release google-geo-type 1.2.0 (#416)
  • 83be724 chore(main): release grpc-google-iam-v1 1.12.0 (#397)
  • 1766762 chore(main): release google-apps-card-v1 1.2.0 (#413)
  • 41762f4 chore(main): release google-cloud-common 1.10.0 (#415)
  • 3466c15 chore(main): release google-shopping-type 1.2.0 (#417)
  • 8a8561f chore(deps): update actions/checkout action to v6 (#406)
  • daa3a55 feat: Regenerate protos and support Ruby min_version 3.2 (#412)
  • 24ca7a6 chore: Refactor Github Action per b/485167538 (#409)
  • Additional commits viewable in compare view

Updates grpc from 1.78.1 to 1.80.0

Release notes

Sourced from grpc's releases.

Release v1.80.0

This is release 1.80.0 (glimmering) of gRPC Core.

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This release contains refinements, improvements, and bug fixes, with highlights listed below.

Core

  • [ssl] Implement TLS private key signer in Python. (#41701)
  • [TLS Credentials]: Private Key Offload Implementation. (#41606)
  • Fix max sockaddr struct size on OpenBSD. (#40454)
  • [core] Enable EventEngine for Python by default, and EventEngine fork support in Python and Ruby. (#41432)
  • [TLS Credentials]: Create InMemoryCertificateProvider to update certificates independently. (#41484)
  • [Ruby] Build/test ruby 4.0 and build native gems with Ruby 4.0 support. (#41324)
  • [EventEngine] Remove an incorrect std::move in DNSServiceResolver constructor. (#41502)
  • [RR and WRR] enable change to connect from a random index. (#41472)
  • [xds] Implement gRFC A101. (#41051)

C++

  • [C++] Add SNI override option to C++ channel credentials options API. (#41460)

C#

  • [C# tools] Option to append Async to server side method names #39010. (#39797)

Objective-C

  • [Fix][Compiler] Plugins fall back to the edition 2023 for older protobuf. (#41357)

PHP

  • [PHP] Disable php infinite recursion check for callback from Core to PHP. (#41835)
  • [PHP] Fix runtime error with PHp8.5 alpha because zend_exception_get_defaul…. (#40337)

Python

  • [Python] Fix GRPC_TRACE not working when absl log initialized in cython. (#41814)
  • Revert "[Python] Align GRPC_ENABLE_FORK_SUPPORT env defaults in core and python (#41455)". (#41769)
  • [Python] Fix AsyncIO Server maximum_concurrent_rpcs enforcement preventing negative active_rpcs count. (#41532)
  • [Python] Docs: correct grpc.Compression references. (#41705)
  • [Python] [Typeguard] Part 4 - Add Typeguard to AIO stack in tests . (#40226)

... (truncated)

Commits
  • f5e2d6e [Release] Bump version to 1.80.0 (on v1.80.x branch) (#41857)
  • 938cfec [subchannel connection scaling] fix when we reset backoff (#41935)
  • 91778be [Backport][v1.80.x][Python] New _create method for aio.Metadata (#41888)
  • be4c1c5 [subchannel] fix crash in connection scaling code (#41853)
  • a71df73 [Release] Bump version to 1.80.0-pre1 (on v1.80.x branch) (#41844)
  • 3ca09e4 [Python] Fix GRPC_TRACE and add test to check the GRPC_TRACE logs print (#41814)
  • 260c6fd [PHP] Disable php infinite recursion check for callback from Core to PHP (#41...
  • e1e1d0a [Bzlmod] Turn off bzlmod for PSM python tests. (#41810)
  • 5a3a5d5 [ssl] Implement TLS private key signer in Python. (#41701)
  • a18875d [PH2][Trivial] Client clean up and reorder
  • Additional commits viewable in compare view

Updates mustermann from 3.0.4 to 3.1.1

Changelog

Sourced from mustermann's changelog.

Changelog

Mustermann follows Semantic Versioning 2.0. Anything documented in the README or via YARD and not declared private is part of the public API.

Unreleased changes

Mustermann 4.0.1

Performance improvements

  • Reduce memory usage by deduplicating internal data structures. This is especially effective when using large Mustermann::Set objects. #159 #160 @​byroot

Stable Releases

Mustermann 4.0.0 (2026-04-27)

Breaking changes

  • Mustermann::Pattern#match will now return Mustermann::Match instead of either MatchData or Mustermann::SimpleMatch. This object behaves similar to the previous return values, but also implements #params and #pattern.
  • Moved Mustermann::Mapper and Mustermann::PatternCache from mustermann to mustermann-contrib.
  • Removed special code for Sinatra 1.x. If you want to use Mustermann with Sinatra, please upgrade to any of the Sinatra versions released since 2017.

New features

  • Mustermann::Rails now supports Rails up to version 8.2 (previously 5.0).
  • Added Mustermann::Hybrid, a pattern that's a union of Sinatra, Rails and URI Template syntax. It is designed to be as compatible as possible with all three syntaxes.
  • Added Mustermann::Set to mustermann, which is a collection of patterns with associated values, designed for building routing tables that dispatch efficiently as the number of routes grows.
  • Reintroduce Mustermann::Router, now based on Mustermann::Set, for demonstration purposes and use in small applications or middleware. Simple and fast.
  • The capture option now supports special class and symbol values, that both set an expected capture pattern and define a params converter.
  • Mustermann::Pattern#+ and Mustermann::Pattern#| now return single patterns instead of composite patterns in significantly more cases, like having non-overlapping captures.
  • Nicer inspect and pretty_print for patterns and other objects.

Here's an example using Mustermann::Hybrid, Mustermann::Set, and the new capture options:

require "mustermann/set"
set = Mustermann::Set.new(type: :hybrid, capture: { id: Integer, user_id: Integer, slug: :slug })
adding values is optional
set.add "/users",                "users.index"
set.add "/users/:id",            "users.show"
set.add "/posts",                "posts.index"
set.add "/users/:user_id/posts", "posts.index"
set.add "/posts/:id(-:slug)",    "posts.show" # slug is optional
match = set.match("/posts/42-awesome-post")
id is automatically converted to an Integer, and slug is available as a string
</tr></table>

... (truncated)

Commits
  • 7445f32 remove visualizer injection into inspect and pretty_print, fixes #153
  • e7721d8 Fix markup in README
  • a33272b Move Rails pattern documentation from mustermann-contrib to mustermann
  • 5cfd230 Fix code example
  • 656eb61 Fix typo
  • 518fb7e Increase version to 3.1.1
  • 8fd53a0 Improve Mustermann::Pattern#hash to reduce the chance of collisions on JRuby ...
  • 6b1eddc fix load order issue when loading mustermann/expander directly
  • c163eaf Merge branch 'main' into reduce-gem-size
  • 418233e bump version to 3.1.0
  • Additional commits viewable in compare view

Updates net-imap from 0.6.3 to 0.6.4

Release notes

Sourced from net-imap's releases.

v0.6.4

What's Changed

🔒 Security

This release contains fixes for multiple vulnerabilities concerning STARTTLS stripping, argument validation, and denial of service attacks.

[!WARNING] ruby/net-imap#664 fixes a STARTTLS stripping vulnerability (GHSA-vcgp-9326-pqcp). Without this fix, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS.

[!IMPORTANT] Argument validation is significantly improved. Several injection vulnerabilities have been fixed: ruby/net-imap#657 fixes CRLF/command/argument injection via Symbol arguments (GHSA-75xq-5h9v-w6px). ruby/net-imap#658 fixes CRLF/command/argument injection via the attr argument to #store/#uid_store (GHSA-hm49-wcqc-g2xg) ruby/net-imap#659 fixes CRLF/command/argument injection via the storage_limit argument to #setquota (GHSA-hm49-wcqc-g2xg). ruby/net-imap#660 fixes CRLF/command injection via RawData (GHSA-hm49-wcqc-g2xg):

  • #search and #uid_search send criteria as raw data, when it is a String
  • #fetch and #uid_fetch send attr as raw data, when it is a String. When attr is an Array, its String members are sent as raw data.

[!CAUTION] RawData does not defend against other forms of argument injection! It is an intentionally low-level API.

[!NOTE] Two denial of service vulnerabilities have been addressed. These are generally only relevant when connecting to an untrusted hostile server (or without TLS).

ruby/net-imap#642 fixes quadratic time complexity when reading large responses containing many string literals (GHSA-q2mw-fvj9-vvcw). ruby/net-imap#654 adds a configurable max_iterations count for SCRAM-* authentication (GHSA-87pf-fpwv-p7m7).

The default ScramAuthenticator#max_iterations is 2**31 - 1 (max 32-bit signed int), which was already OpenSSL's maximum value. It provides no protection against hostile servers unless it is explicitly set to a lower value by the user.

Breaking Changes

  • ResponseReader memoizes Config#max_response_size in ruby/net-imap#642. Changes to #max_response_size now take effect once per response, not on every IO#read. NOTE: It is not expected that this will affect any current usage. See the PR for details.

Added

Fixed

... (truncated)

Commits
  • 3e49067 🔖 Bump version to 0.6.4
  • 0ede4c4 🔀 Merge pull request #664 from ruby/security/STARTTLS-stripping
  • 51ae360 ♻️ Add command response handler before command is sent
  • 24d5c77 🔒🥅 Handle tagged "OK" to incomplete command
  • 62eea6f 🔒🥅 Ensure STARTTLS tagged response was handled
  • 46636ca ❌🔒 Add failing test for STARTTLS stripping
  • e3b0105 ✅♻️ Inline current STARTLS stripping test
  • be32e71 📚 Improve documentation of RawData arguments

…directory with 72 updates

Bumps the bundler-production-dependencies group with 16 updates in the /src/email directory:

| Package | From | To |
| --- | --- | --- |
| [puma](https://github.com/puma/puma) | `7.2.0` | `8.0.1` |
| [google-protobuf](https://github.com/protocolbuffers/protobuf) | `4.34.0` | `4.35.0` |
| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-ruby) | `1.10.0` | `1.12.0` |
| [opentelemetry-common](https://github.com/open-telemetry/opentelemetry-ruby) | `0.23.0` | `0.25.0` |
| [opentelemetry-logs-sdk](https://github.com/open-telemetry/opentelemetry-ruby) | `0.4.0` | `0.6.0` |
| [opentelemetry-metrics-sdk](https://github.com/open-telemetry/opentelemetry-ruby) | `0.12.0` | `0.14.0` |
| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-ruby) | `0.31.1` | `0.34.0` |
| [opentelemetry-exporter-otlp-metrics](https://github.com/open-telemetry/opentelemetry-ruby) | `0.6.1` | `0.9.0` |
| [opentelemetry-exporter-otlp-logs](https://github.com/open-telemetry/opentelemetry-ruby) | `0.2.2` | `0.5.0` |
| [opentelemetry-instrumentation-all](https://github.com/open-telemetry/opentelemetry-ruby-contrib) | `0.90.1` | `0.93.0` |
| [openfeature-sdk](https://github.com/open-feature/ruby-sdk) | `0.6.4` | `0.6.5` |
| [grpc](https://github.com/google/grpc) | `1.78.1` | `1.80.0` |
| [mustermann](https://github.com/sinatra/mustermann) | `3.0.4` | `3.1.1` |
| [net-imap](https://github.com/ruby/net-imap) | `0.6.3` | `0.6.4` |
| [rack](https://github.com/rack/rack) | `3.2.5` | `3.2.6` |
| [rack-session](https://github.com/rack/rack-session) | `2.1.1` | `2.1.2` |



Updates `puma` from 7.2.0 to 8.0.1
- [Release notes](https://github.com/puma/puma/releases)
- [Changelog](https://github.com/puma/puma/blob/main/History.md)
- [Commits](puma/puma@v7.2.0...v8.0.1)

Updates `google-protobuf` from 4.34.0 to 4.35.0
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](https://github.com/protocolbuffers/protobuf/commits)

Updates `opentelemetry-sdk` from 1.10.0 to 1.12.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-sdk/v1.10.0...opentelemetry-sdk/v1.12.0)

Updates `opentelemetry-common` from 0.23.0 to 0.25.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-common/v0.23.0...opentelemetry-common/v0.25.0)

Updates `opentelemetry-logs-sdk` from 0.4.0 to 0.6.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-logs-sdk/v0.4.0...opentelemetry-logs-sdk/v0.6.0)

Updates `opentelemetry-metrics-sdk` from 0.12.0 to 0.14.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-metrics-sdk/v0.12.0...opentelemetry-metrics-sdk/v0.14.0)

Updates `opentelemetry-exporter-otlp` from 0.31.1 to 0.34.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-exporter-otlp/v0.31.1...opentelemetry-exporter-otlp/v0.34.0)

Updates `opentelemetry-exporter-otlp-metrics` from 0.6.1 to 0.9.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-exporter-otlp-metrics/v0.6.1...opentelemetry-exporter-otlp-metrics/v0.9.0)

Updates `opentelemetry-exporter-otlp-logs` from 0.2.2 to 0.5.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-exporter-otlp-logs/v0.2.2...opentelemetry-exporter-otlp-logs/v0.5.0)

Updates `opentelemetry-instrumentation-all` from 0.90.1 to 0.93.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-all/v0.90.1...opentelemetry-instrumentation-all/v0.93.0)

Updates `openfeature-sdk` from 0.6.4 to 0.6.5
- [Release notes](https://github.com/open-feature/ruby-sdk/releases)
- [Changelog](https://github.com/open-feature/ruby-sdk/blob/main/CHANGELOG.md)
- [Commits](open-feature/ruby-sdk@v0.6.4...v0.6.5)

Updates `bigdecimal` from 4.0.1 to 4.1.2
- [Release notes](https://github.com/ruby/bigdecimal/releases)
- [Changelog](https://github.com/ruby/bigdecimal/blob/master/CHANGES.md)
- [Commits](ruby/bigdecimal@v4.0.1...v4.1.2)

Updates `googleapis-common-protos-types` from 1.22.0 to 1.23.0
- [Release notes](https://github.com/googleapis/common-protos-ruby/releases)
- [Commits](googleapis/common-protos-ruby@googleapis-common-protos-types/v1.22.0...googleapis-common-protos-types/v1.23.0)

Updates `grpc` from 1.78.1 to 1.80.0
- [Release notes](https://github.com/google/grpc/releases)
- [Commits](grpc/grpc@v1.78.1...v1.80.0)

Updates `mustermann` from 3.0.4 to 3.1.1
- [Changelog](https://github.com/sinatra/mustermann/blob/main/CHANGELOG.md)
- [Commits](sinatra/mustermann@v3.0.4...v3.1.1)

Updates `net-imap` from 0.6.3 to 0.6.4
- [Release notes](https://github.com/ruby/net-imap/releases)
- [Commits](ruby/net-imap@v0.6.3...v0.6.4)

Updates `opentelemetry-api` from 1.7.0 to 1.10.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-api/v1.7.0...opentelemetry-api/v1.10.0)

Updates `opentelemetry-helpers-mysql` from 0.4.0 to 0.6.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-helpers-mysql/v0.4.0...opentelemetry-helpers-mysql/v0.6.0)

Updates `opentelemetry-helpers-sql` from 0.3.0 to 0.4.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-helpers-sql/v0.3.0...opentelemetry-helpers-sql/v0.4.0)

Updates `opentelemetry-helpers-sql-processor` from 0.4.0 to 0.5.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-helpers-sql-processor/v0.4.0...opentelemetry-helpers-sql-processor/v0.5.0)

Updates `opentelemetry-instrumentation-action_mailer` from 0.6.1 to 0.8.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-action_mailer/v0.6.1...opentelemetry-instrumentation-action_mailer/v0.8.0)

Updates `opentelemetry-instrumentation-action_pack` from 0.15.1 to 0.18.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-action_pack/v0.15.1...opentelemetry-instrumentation-action_pack/v0.18.0)

Updates `opentelemetry-instrumentation-action_view` from 0.11.2 to 0.13.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-action_view/v0.11.2...opentelemetry-instrumentation-action_view/v0.13.0)

Updates `opentelemetry-instrumentation-active_job` from 0.10.1 to 0.12.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-active_job/v0.10.1...opentelemetry-instrumentation-active_job/v0.12.0)

Updates `opentelemetry-instrumentation-active_model_serializers` from 0.24.0 to 0.25.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-active_model_serializers/v0.24.0...opentelemetry-instrumentation-active_model_serializers/v0.25.0)

Updates `opentelemetry-instrumentation-active_record` from 0.11.1 to 0.13.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-active_record/v0.11.1...opentelemetry-instrumentation-active_record/v0.13.0)

Updates `opentelemetry-instrumentation-active_storage` from 0.3.1 to 0.5.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-active_storage/v0.3.1...opentelemetry-instrumentation-active_storage/v0.5.0)

Updates `opentelemetry-instrumentation-active_support` from 0.10.1 to 0.12.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-active_support/v0.10.1...opentelemetry-instrumentation-active_support/v0.12.0)

Updates `opentelemetry-instrumentation-anthropic` from 0.3.0 to 0.5.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-anthropic/v0.3.0...opentelemetry-instrumentation-anthropic/v0.5.0)

Updates `opentelemetry-instrumentation-aws_lambda` from 0.6.0 to 0.7.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-aws_lambda/v0.6.0...opentelemetry-instrumentation-aws_lambda/v0.7.0)

Updates `opentelemetry-instrumentation-aws_sdk` from 0.11.0 to 0.12.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-aws_sdk/v0.11.0...opentelemetry-instrumentation-aws_sdk/v0.12.0)

Updates `opentelemetry-instrumentation-base` from 0.25.0 to 0.26.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-base/v0.25.0...opentelemetry-instrumentation-base/v0.26.0)

Updates `opentelemetry-instrumentation-bunny` from 0.24.0 to 0.25.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-bunny/v0.24.0...opentelemetry-instrumentation-bunny/v0.25.0)

Updates `opentelemetry-instrumentation-concurrent_ruby` from 0.24.0 to 0.25.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-concurrent_ruby/v0.24.0...opentelemetry-instrumentation-concurrent_ruby/v0.25.0)

Updates `opentelemetry-instrumentation-dalli` from 0.29.2 to 0.30.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-dalli/v0.29.2...opentelemetry-instrumentation-dalli/v0.30.0)

Updates `opentelemetry-instrumentation-delayed_job` from 0.25.1 to 0.26.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-delayed_job/v0.25.1...opentelemetry-instrumentation-delayed_job/v0.26.0)

Updates `opentelemetry-instrumentation-ethon` from 0.27.0 to 0.29.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-ethon/v0.27.0...opentelemetry-instrumentation-ethon/v0.29.0)

Updates `opentelemetry-instrumentation-excon` from 0.27.0 to 0.29.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-excon/v0.27.0...opentelemetry-instrumentation-excon/v0.29.1)

Updates `opentelemetry-instrumentation-faraday` from 0.31.0 to 0.33.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-faraday/v0.31.0...opentelemetry-instrumentation-faraday/v0.33.0)

Updates `opentelemetry-instrumentation-grape` from 0.5.1 to 0.7.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-grape/v0.5.1...opentelemetry-instrumentation-grape/v0.7.0)

Updates `opentelemetry-instrumentation-graphql` from 0.31.2 to 0.32.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-graphql/v0.31.2...opentelemetry-instrumentation-graphql/v0.32.0)

Updates `opentelemetry-instrumentation-grpc` from 0.4.1 to 0.5.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-grpc/v0.4.1...opentelemetry-instrumentation-grpc/v0.5.0)

Updates `opentelemetry-instrumentation-gruf` from 0.5.0 to 0.6.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-gruf/v0.5.0...opentelemetry-instrumentation-gruf/v0.6.0)

Updates `opentelemetry-instrumentation-http` from 0.28.0 to 0.30.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-http/v0.28.0...opentelemetry-instrumentation-http/v0.30.0)

Updates `opentelemetry-instrumentation-http_client` from 0.27.0 to 0.29.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-http_client/v0.27.0...opentelemetry-instrumentation-http_client/v0.29.0)

Updates `opentelemetry-instrumentation-httpx` from 0.6.1 to 0.8.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-httpx/v0.6.1...opentelemetry-instrumentation-httpx/v0.8.0)

Updates `opentelemetry-instrumentation-koala` from 0.23.0 to 0.24.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-koala/v0.23.0...opentelemetry-instrumentation-koala/v0.24.0)

Updates `opentelemetry-instrumentation-lmdb` from 0.25.0 to 0.26.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-lmdb/v0.25.0...opentelemetry-instrumentation-lmdb/v0.26.0)

Updates `opentelemetry-instrumentation-mongo` from 0.25.0 to 0.26.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-mongo/v0.25.0...opentelemetry-instrumentation-mongo/v0.26.0)

Updates `opentelemetry-instrumentation-mysql2` from 0.33.0 to 0.34.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-mysql2/v0.33.0...opentelemetry-instrumentation-mysql2/v0.34.0)

Updates `opentelemetry-instrumentation-net_http` from 0.27.0 to 0.29.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-net_http/v0.27.0...opentelemetry-instrumentation-net_http/v0.29.0)

Updates `opentelemetry-instrumentation-pg` from 0.35.0 to 0.36.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-pg/v0.35.0...opentelemetry-instrumentation-pg/v0.36.0)

Updates `opentelemetry-instrumentation-que` from 0.12.0 to 0.13.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-que/v0.12.0...opentelemetry-instrumentation-que/v0.13.0)

Updates `opentelemetry-instrumentation-racecar` from 0.6.1 to 0.7.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-racecar/v0.6.1...opentelemetry-instrumentation-racecar/v0.7.0)

Updates `opentelemetry-instrumentation-rack` from 0.29.0 to 0.31.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-rack/v0.29.0...opentelemetry-instrumentation-rack/v0.31.0)

Updates `opentelemetry-instrumentation-rails` from 0.39.1 to 0.42.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-rails/v0.39.1...opentelemetry-instrumentation-rails/v0.42.0)

Updates `opentelemetry-instrumentation-rake` from 0.5.0 to 0.6.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-rake/v0.5.0...opentelemetry-instrumentation-rake/v0.6.0)

Updates `opentelemetry-instrumentation-rdkafka` from 0.9.0 to 0.10.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-rdkafka/v0.9.0...opentelemetry-instrumentation-rdkafka/v0.10.0)

Updates `opentelemetry-instrumentation-redis` from 0.28.0 to 0.29.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-redis/v0.28.0...opentelemetry-instrumentation-redis/v0.29.0)

Updates `opentelemetry-instrumentation-resque` from 0.8.0 to 0.9.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-resque/v0.8.0...opentelemetry-instrumentation-resque/v0.9.0)

Updates `opentelemetry-instrumentation-restclient` from 0.26.0 to 0.28.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-restclient/v0.26.0...opentelemetry-instrumentation-restclient/v0.28.0)

Updates `opentelemetry-instrumentation-ruby_kafka` from 0.24.0 to 0.25.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-ruby_kafka/v0.24.0...opentelemetry-instrumentation-ruby_kafka/v0.25.0)

Updates `opentelemetry-instrumentation-sidekiq` from 0.28.1 to 0.29.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-sidekiq/v0.28.1...opentelemetry-instrumentation-sidekiq/v0.29.0)

Updates `opentelemetry-instrumentation-sinatra` from 0.28.0 to 0.30.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-sinatra/v0.28.0...opentelemetry-instrumentation-sinatra/v0.30.0)

Updates `opentelemetry-instrumentation-trilogy` from 0.66.0 to 0.68.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](open-telemetry/opentelemetry-ruby-contrib@opentelemetry-instrumentation-trilogy/v0.66.0...opentelemetry-instrumentation-trilogy/v0.68.0)

Updates `opentelemetry-logs-api` from 0.2.0 to 0.4.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-logs-api/v0.2.0...opentelemetry-logs-api/v0.4.0)

Updates `opentelemetry-metrics-api` from 0.4.0 to 0.6.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-metrics-api/v0.4.0...opentelemetry-metrics-api/v0.6.0)

Updates `opentelemetry-registry` from 0.4.0 to 0.6.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-registry/v0.4.0...opentelemetry-registry/v0.6.0)

Updates `opentelemetry-semantic_conventions` from 1.36.0 to 1.37.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](open-telemetry/opentelemetry-ruby@opentelemetry-semantic_conventions/v1.36.0...opentelemetry-semantic_conventions/v1.37.1)

Updates `rack` from 3.2.5 to 3.2.6
- [Release notes](https://github.com/rack/rack/releases)
- [Changelog](https://github.com/rack/rack/blob/main/CHANGELOG.md)
- [Commits](rack/rack@v3.2.5...v3.2.6)

Updates `rack-session` from 2.1.1 to 2.1.2
- [Release notes](https://github.com/rack/rack-session/releases)
- [Changelog](https://github.com/rack/rack-session/blob/main/releases.md)
- [Commits](rack/rack-session@v2.1.1...v2.1.2)

Updates `rake` from 13.3.1 to 13.4.2
- [Release notes](https://github.com/ruby/rake/releases)
- [Changelog](https://github.com/ruby/rake/blob/master/History.rdoc)
- [Commits](ruby/rake@v13.3.1...v13.4.2)

---
updated-dependencies:
- dependency-name: puma
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bundler-production-dependencies
- dependency-name: google-protobuf
  dependency-version: 4.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-sdk
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-common
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-logs-sdk
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-metrics-sdk
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-exporter-otlp
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-exporter-otlp-metrics
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-exporter-otlp-logs
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-all
  dependency-version: 0.93.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: openfeature-sdk
  dependency-version: 0.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bundler-production-dependencies
- dependency-name: bigdecimal
  dependency-version: 4.1.2
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: googleapis-common-protos-types
  dependency-version: 1.23.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: grpc
  dependency-version: 1.80.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: mustermann
  dependency-version: 3.1.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: net-imap
  dependency-version: 0.6.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-api
  dependency-version: 1.10.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-helpers-mysql
  dependency-version: 0.6.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-helpers-sql
  dependency-version: 0.4.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-helpers-sql-processor
  dependency-version: 0.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-action_mailer
  dependency-version: 0.8.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-action_pack
  dependency-version: 0.18.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-action_view
  dependency-version: 0.13.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-active_job
  dependency-version: 0.12.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-active_model_serializers
  dependency-version: 0.25.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-active_record
  dependency-version: 0.13.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-active_storage
  dependency-version: 0.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-active_support
  dependency-version: 0.12.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-anthropic
  dependency-version: 0.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-aws_lambda
  dependency-version: 0.7.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-aws_sdk
  dependency-version: 0.12.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-base
  dependency-version: 0.26.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-bunny
  dependency-version: 0.25.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-concurrent_ruby
  dependency-version: 0.25.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-dalli
  dependency-version: 0.30.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-delayed_job
  dependency-version: 0.26.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-ethon
  dependency-version: 0.29.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-excon
  dependency-version: 0.29.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-faraday
  dependency-version: 0.33.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-grape
  dependency-version: 0.7.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-graphql
  dependency-version: 0.32.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-grpc
  dependency-version: 0.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-gruf
  dependency-version: 0.6.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-http
  dependency-version: 0.30.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-http_client
  dependency-version: 0.29.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-httpx
  dependency-version: 0.8.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-koala
  dependency-version: 0.24.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-lmdb
  dependency-version: 0.26.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-mongo
  dependency-version: 0.26.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-mysql2
  dependency-version: 0.34.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-net_http
  dependency-version: 0.29.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-pg
  dependency-version: 0.36.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-que
  dependency-version: 0.13.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-racecar
  dependency-version: 0.7.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-rack
  dependency-version: 0.31.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-rails
  dependency-version: 0.42.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-rake
  dependency-version: 0.6.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-rdkafka
  dependency-version: 0.10.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-redis
  dependency-version: 0.29.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-resque
  dependency-version: 0.9.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-restclient
  dependency-version: 0.28.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-ruby_kafka
  dependency-version: 0.25.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-sidekiq
  dependency-version: 0.29.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-sinatra
  dependency-version: 0.30.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-instrumentation-trilogy
  dependency-version: 0.68.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-logs-api
  dependency-version: 0.4.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-metrics-api
  dependency-version: 0.6.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-registry
  dependency-version: 0.6.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: opentelemetry-semantic_conventions
  dependency-version: 1.37.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
- dependency-name: rack
  dependency-version: 3.2.6
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: bundler-production-dependencies
- dependency-name: rack-session
  dependency-version: 2.1.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: bundler-production-dependencies
- dependency-name: rake
  dependency-version: 13.4.2
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: bundler-production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants