Skip to content

chore: [TESIS-157] bump brakeman to 8.1.0 so the security scan runs again - #112

Merged
LauAubert merged 1 commit into
masterfrom
TESIS-999024-brakeman-8-1
Oct 2, 2026
Merged

LauAubert merged 1 commit into
masterfrom
TESIS-999024-brakeman-8-1

Conversation

@LauAubert

@LauAubert LauAubert commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Ticket de Jira

https://proyectofinalfrlp.atlassian.net/browse/TESIS-157

ID provisorio: se reemplaza por la clave real al cargar la card en Jira. Card: cards/024.md.


Descripción

bin/brakeman (el que genera Rails) agrega --ensure-latest: si existe una versión más nueva de Brakeman, sale con status 5 sin escanear. Desde que se publicó Brakeman 8.1.0, el job scan_ruby falla en todos los PRs abiertos con:

Brakeman 8.0.6 is not the latest version 8.1.0
##[error]Process completed with exit code 5.

No es un problema del código de ningún PR: el último CI verde de master corrió antes del release. Los grupos de Dependabot (#96, #97) no incluyen Brakeman.

  • Actualiza brakeman de 8.0.6 a 8.1.0 en Gemfile.lock: sólo la entrada y su checksum. Las dependencias son las mismas (racc).
  • El lockfile no suma la plataforma local (arm64-darwin): se editó sobre el de master para no arrastrar ese ruido.

Después de mergear, los PRs abiertos necesitan traer master para que scan_ruby vuelva a pasar.

A futuro: --ensure-latest va a volver a romper CI con cada release. Se puede sacar de bin/brakeman (y dejar que Dependabot proponga la actualización) o sumar brakeman a un grupo de Dependabot. Es una decisión del equipo; este PR no la toma.


Evidencia visual

N/A


Cómo probar

  1. bundle install && bin/brakeman --no-pager → «No warnings found», sin el aviso de versión.
  2. El job scan_ruby de este PR pasa.

Impacto y consideraciones

¿Introduce breaking changes?
No

¿Requiere nuevas variables de entorno?
No

¿Afecta la arquitectura o genera un nuevo patrón?
No

🤖 Generated with Claude Code

…s again

bin/brakeman runs with --ensure-latest, so the release of Brakeman 8.1.0
made the scan_ruby job of every pull request exit with status 5 before
scanning anything ("Brakeman 8.0.6 is not the latest version 8.1.0"). The
dependabot groups do not include it.

Only the brakeman entry and its checksum change in Gemfile.lock; its
dependencies are the same.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@LauAubert
LauAubert marked this pull request as ready for review October 2, 2026 12:23
@LauAubert
LauAubert requested a review from a team as a code owner October 2, 2026 12:23
@LauAubert
LauAubert merged commit fc5e96a into master Oct 2, 2026
4 checks passed
@LauAubert LauAubert changed the title chore: [TESIS-999024] bump brakeman to 8.1.0 so the security scan runs again chore: [TESIS-157] bump brakeman to 8.1.0 so the security scan runs again Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant