chore: [TESIS-157] bump brakeman to 8.1.0 so the security scan runs again - #112
Merged
Merged
Conversation
…s again
bin/brakeman runs with --ensure-latest, so the release of Brakeman 8.1.0
made the scan_ruby job of every pull request exit with status 5 before
scanning anything ("Brakeman 8.0.6 is not the latest version 8.1.0"). The
dependabot groups do not include it.
Only the brakeman entry and its checksum change in Gemfile.lock; its
dependencies are the same.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
LauAubert
marked this pull request as ready for review
October 2, 2026 12:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket de Jira
https://proyectofinalfrlp.atlassian.net/browse/TESIS-157
Descripción
bin/brakeman(el que genera Rails) agrega--ensure-latest: si existe una versión más nueva de Brakeman, sale con status 5 sin escanear. Desde que se publicó Brakeman 8.1.0, el jobscan_rubyfalla en todos los PRs abiertos con:No es un problema del código de ningún PR: el último CI verde de
mastercorrió antes del release. Los grupos de Dependabot (#96, #97) no incluyen Brakeman.brakemande 8.0.6 a 8.1.0 enGemfile.lock: sólo la entrada y su checksum. Las dependencias son las mismas (racc).arm64-darwin): se editó sobre el demasterpara no arrastrar ese ruido.Después de mergear, los PRs abiertos necesitan traer
masterpara quescan_rubyvuelva a pasar.A futuro:
--ensure-latestva a volver a romper CI con cada release. Se puede sacar debin/brakeman(y dejar que Dependabot proponga la actualización) o sumarbrakemana un grupo de Dependabot. Es una decisión del equipo; este PR no la toma.Evidencia visual
N/A
Cómo probar
bundle install && bin/brakeman --no-pager→ «No warnings found», sin el aviso de versión.scan_rubyde este PR pasa.Impacto y consideraciones
¿Introduce breaking changes?
No
¿Requiere nuevas variables de entorno?
No
¿Afecta la arquitectura o genera un nuevo patrón?
No
🤖 Generated with Claude Code