Updates `pg` from 1.6.3 to 1.7.0
- [Changelog](https://github.com/ged/ruby-pg/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ged/ruby-pg/compare/v1.6.3...v1.7.0)
Updates `autoprefixer-rails` from 10.4.21.0 to 10.6.1.0
- [Changelog](https://github.com/ai/autoprefixer-rails/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ai/autoprefixer-rails/compare/10.4.21.0...10.6.1.0)
Updates `dalli` from 5.1.1 to 5.2.2
- [Release notes](https://github.com/petergoldstein/dalli/releases)
- [Changelog](https://github.com/petergoldstein/dalli/blob/main/CHANGELOG.md)
- [Commits](https://github.com/petergoldstein/dalli/compare/v5.1.1...v5.2.2)
Updates `opentelemetry-exporter-otlp` from 0.36.0 to 0.37.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby/compare/opentelemetry-exporter-otlp/v0.36.0...opentelemetry-exporter-otlp/v0.37.0)
Updates `opentelemetry-instrumentation-all` from 0.96.0 to 0.97.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby-contrib/compare/opentelemetry-instrumentation-all/v0.96.0...opentelemetry-instrumentation-all/v0.97.0)
Updates `sentry-delayed_job` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getsentry/sentry-ruby/compare/7.0.0...7.1.0)
Updates `sentry-rails` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getsentry/sentry-ruby/compare/7.0.0...7.1.0)
Updates `sentry-ruby` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getsentry/sentry-ruby/compare/7.0.0...7.1.0)
Updates `aws-sdk-s3` from 1.232.2 to 1.233.1
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases)
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-ruby/commits)
Updates `image_processing` from 2.1.0 to 2.2.0
- [Changelog](https://github.com/janko/image_processing/blob/master/CHANGELOG.md)
- [Commits](https://github.com/janko/image_processing/compare/v2.1.0...v2.2.0)
Updates `noticed` from 3.0.0 to 3.1.0
- [Release notes](https://github.com/excid3/noticed/releases)
- [Changelog](https://github.com/excid3/noticed/blob/main/CHANGELOG.md)
- [Commits](https://github.com/excid3/noticed/compare/v3.0.0...v3.1.0)
Updates `listen` from 3.10.0 to 3.10.1
- [Release notes](https://github.com/guard/listen/releases)
- [Commits](https://github.com/guard/listen/compare/v3.10.0...v3.10.1)
Updates `brakeman` from 8.0.6 to 8.1.0
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](https://github.com/presidentbeef/brakeman/compare/v8.0.6...v8.1.0)
Updates `pg_query` from 6.2.2 to 6.2.5
- [Changelog](https://github.com/pganalyze/pg_query/blob/main/CHANGELOG.md)
- [Commits](https://github.com/pganalyze/pg_query/compare/v6.2.2...v6.2.5)
Updates `selenium-webdriver` from 4.49.0 to 4.50.0
- [Release notes](https://github.com/SeleniumHQ/selenium/releases)
- [Changelog](https://github.com/SeleniumHQ/selenium/blob/trunk/rb/CHANGES)
- [Commits](https://github.com/SeleniumHQ/selenium/compare/selenium-4.49.0...selenium-4.50.0)
Updates `database_consistency` from 3.0.13 to 3.0.14
- [Changelog](https://github.com/djezzzl/database_consistency/blob/master/CHANGELOG.md)
- [Commits](https://github.com/djezzzl/database_consistency/compare/v3.0.13...v3.0.14)
Updates `aws-partitions` from 1.1291.0 to 1.1293.0
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases)
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-partitions/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-ruby/commits)
Updates `date` from 3.5.1 to 3.6.0
- [Release notes](https://github.com/ruby/date/releases)
- [Commits](https://github.com/ruby/date/compare/v3.5.1...v3.6.0)
Updates `googleapis-common-protos-types` from 1.20.0 to 1.23.0
- [Release notes](https://github.com/googleapis/common-protos-ruby/releases)
- [Commits](https://github.com/googleapis/common-protos-ruby/compare/googleapis-common-protos-types/v1.20.0...googleapis-common-protos-types/v1.23.0)
Updates `opentelemetry-common` from 0.25.1 to 0.25.2
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby/compare/opentelemetry-common/v0.25.1...opentelemetry-common/v0.25.2)
Updates `opentelemetry-exporter-otlp-common` from 0.2.0 to 0.3.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby/compare/opentelemetry-exporter-otlp-common/v0.2.0...opentelemetry-exporter-otlp-common/v0.3.0)
Updates `opentelemetry-instrumentation-aws_lambda` from 0.7.0 to 0.7.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby-contrib/compare/opentelemetry-instrumentation-aws_lambda/v0.7.0...opentelemetry-instrumentation-aws_lambda/v0.7.1)
Updates `opentelemetry-instrumentation-base` from 0.26.1 to 0.27.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby-contrib/compare/opentelemetry-instrumentation-base/v0.26.1...opentelemetry-instrumentation-base/v0.27.0)
Updates `opentelemetry-instrumentation-lmdb` from 0.26.1 to 0.27.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby-contrib/compare/opentelemetry-instrumentation-lmdb/v0.26.1...opentelemetry-instrumentation-lmdb/v0.27.0)
Updates `opentelemetry-instrumentation-net_http` from 0.29.1 to 0.29.2
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby-contrib/compare/opentelemetry-instrumentation-net_http/v0.29.1...opentelemetry-instrumentation-net_http/v0.29.2)
Updates `opentelemetry-instrumentation-rack` from 0.31.1 to 0.31.2
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby-contrib/compare/opentelemetry-instrumentation-rack/v0.31.1...opentelemetry-instrumentation-rack/v0.31.2)
Updates `opentelemetry-instrumentation-sinatra` from 0.30.0 to 0.30.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-ruby-contrib/releases)
- [Commits](https://github.com/open-telemetry/opentelemetry-ruby-contrib/compare/opentelemetry-instrumentation-sinatra/v0.30.0...opentelemetry-instrumentation-sinatra/v0.30.1)
Tom Hughes [Thu, 8 Oct 2026 17:47:14 +0000 (18:47 +0100)]
Release pinning of dartsass-sprockets and related gems
We keep sass-embedded pinned to a version below 3.0.0 as some
of the deprecation warnings from bootstrap are for things which
are planned to be removed in that version.
dependabot[bot] [Wed, 7 Oct 2026 23:13:16 +0000 (23:13 +0000)]
Bump the dependencies group with 3 updates
Bumps the dependencies group with 3 updates: [terra-draw](https://github.com/JamesLMilner/terra-draw), [eslint](https://github.com/eslint/eslint) and [globals](https://github.com/sindresorhus/globals).
Updates `terra-draw` from 1.35.0 to 1.36.0
- [Release notes](https://github.com/JamesLMilner/terra-draw/releases)
- [Changelog](https://github.com/JamesLMilner/terra-draw/blob/main/release.js)
- [Commits](https://github.com/JamesLMilner/terra-draw/compare/terra-draw@1.35.0...terra-draw@1.36.0)
Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.11.0...v10.12.0)
Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](https://github.com/sindresorhus/globals/compare/v17.12.0...v17.13.0)
Andy Allan [Thu, 1 Oct 2026 12:40:54 +0000 (13:40 +0100)]
Fix N+1 queries for comment authors in the notes API
Preload the authors of note comments, and of the notes themselves for
the RSS feeds, when rendering notes from the API.
The tests now use notes with comments by at least three different
users, as prosopite doesn't always detect an N+1 query with only two
records - the first query in a process can have a different call stack
while the association's statement cache is built.
Andy Allan [Thu, 1 Oct 2026 10:50:57 +0000 (11:50 +0100)]
Detect N+1 queries in tests using prosopite
Each request handled by the tests (controllers, integration and system)
is scanned separately for N+1 queries using prosopite's rack middleware,
as is each job performed outside of a request. The test fails if any are found.
Jobs performed during a request aren't scanned, as their queries would
otherwise count towards the request's. That would make a request that triggers
three email notifications look like an N+1 query, whereas in reality each job
is performed separately.
Existing N+1 queries are allowed when any of the files listed in
test/prosopite_todo.yml are in the call stack. This means we can work
through that list, but avoid adding new N+1 queries in other parts of our code.
Updates `activerecord-postgis` from 0.6.0 to 0.6.1
- [Release notes](https://github.com/seuros/activerecord-postgis/releases)
- [Changelog](https://github.com/seuros/activerecord-postgis/blob/master/CHANGELOG.md)
- [Commits](https://github.com/seuros/activerecord-postgis/compare/activerecord-postgis/v0.6.0...activerecord-postgis/v0.6.1)
Updates `actionpack-page_caching` from 1.2.4 to 1.2.5
- [Release notes](https://github.com/rails/actionpack-page_caching/releases)
- [Changelog](https://github.com/rails/actionpack-page_caching/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rails/actionpack-page_caching/compare/v1.2.4...v1.2.5)
Updates `doorkeeper` from 5.9.7 to 5.9.9
- [Release notes](https://github.com/doorkeeper-gem/doorkeeper/releases)
- [Changelog](https://github.com/doorkeeper-gem/doorkeeper/blob/main/CHANGELOG.md)
- [Commits](https://github.com/doorkeeper-gem/doorkeeper/compare/v5.9.7...v5.9.9)
Updates `doorkeeper-openid_connect` from 1.10.5 to 2.0.0
- [Release notes](https://github.com/doorkeeper-gem/doorkeeper-openid_connect/releases)
- [Changelog](https://github.com/doorkeeper-gem/doorkeeper-openid_connect/blob/master/CHANGELOG.md)
- [Commits](https://github.com/doorkeeper-gem/doorkeeper-openid_connect/compare/v1.10.5...v2.0.0)
Updates `dalli` from 5.1.0 to 5.1.1
- [Release notes](https://github.com/petergoldstein/dalli/releases)
- [Changelog](https://github.com/petergoldstein/dalli/blob/main/CHANGELOG.md)
- [Commits](https://github.com/petergoldstein/dalli/compare/v5.1.0...v5.1.1)
Updates `aws-sdk-s3` from 1.232.1 to 1.232.2
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases)
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-ruby/commits)
Updates `herb` from 0.10.4 to 0.11.0
- [Release notes](https://github.com/marcoroth/herb/releases)
- [Commits](https://github.com/marcoroth/herb/compare/v0.10.4...v0.11.0)
Updates `database_consistency` from 3.0.12 to 3.0.13
- [Changelog](https://github.com/djezzzl/database_consistency/blob/master/CHANGELOG.md)
- [Commits](https://github.com/djezzzl/database_consistency/compare/v3.0.12...v3.0.13)
Updates `aws-partitions` from 1.1289.0 to 1.1291.0
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases)
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-partitions/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-ruby/commits)
Updates `bindata` from 3.0.0 to 3.0.1
- [Changelog](https://github.com/dmendel/bindata/blob/master/ChangeLog.rdoc)
- [Commits](https://github.com/dmendel/bindata/compare/v3.0.0...v3.0.1)
Bumps the dependencies group with 2 updates: [tag2link](https://github.com/JOSM/tag2link) and [@herb-tools/linter](https://github.com/marcoroth/herb/tree/HEAD/javascript/packages/linter).
Updates `tag2link` from 2026.8.21 to 2026.9.21
- [Release notes](https://github.com/JOSM/tag2link/releases)
- [Commits](https://github.com/JOSM/tag2link/compare/2026.8.21...2026.9.21)
Updates `@herb-tools/linter` from 0.10.4 to 0.11.0
- [Release notes](https://github.com/marcoroth/herb/releases)
- [Commits](https://github.com/marcoroth/herb/commits/v0.11.0/javascript/packages/linter)
Keep auth provider logos styleable after SVG optimisation
Give the Apple and GitHub logo background/foreground svgo-stable bg/fg
classes and style those instead of rect/path, and drop the svg
width/height from apple, github and microsoft so their viewBox survives.