Skip to content

chore(deps): bump action_text-trix from 2.1.17 to 2.1.18#2543

Merged
mroderick merged 1 commit intomasterfrom
dependabot/bundler/action_text-trix-2.1.18
Apr 12, 2026
Merged

chore(deps): bump action_text-trix from 2.1.17 to 2.1.18#2543
mroderick merged 1 commit intomasterfrom
dependabot/bundler/action_text-trix-2.1.18

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 29, 2026

Bumps action_text-trix from 2.1.17 to 2.1.18.

Release notes

Sourced from action_text-trix's releases.

v2.1.18

Security

Infrastructure/CI

Full Changelog: basecamp/trix@v2.1.17...v2.1.18

Commits

@dependabot dependabot bot added dependencies ruby Pull requests that update Ruby code labels Mar 29, 2026
Bumps [action_text-trix](https://github.com/basecamp/trix) from 2.1.17 to 2.1.18.
- [Release notes](https://github.com/basecamp/trix/releases)
- [Commits](basecamp/trix@v2.1.17...v2.1.18)

---
updated-dependencies:
- dependency-name: action_text-trix
  dependency-version: 2.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/bundler/action_text-trix-2.1.18 branch from 0da5682 to bac5733 Compare April 11, 2026 15:04
Copy link
Copy Markdown
Collaborator

@mroderick mroderick left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Upgrade Review: action_text-trix v2.1.17 → v2.1.18

PR Scope

Dependency-only - Only Gemfile.lock modified (3 gems updated: action_text-trix, json, minitest)

Changes in Dependency

  • Security: Fix XSS via javascript: URI in JSON drag-drop deserialization (#1293)
  • Infrastructure: Harden GitHub Actions workflows

Usage in Repository

NONE - action_text-trix is in Gemfile but never used in the codebase:

  • No ActionText models, controllers, or views
  • No references to action_text in any code
  • Only present as transitive dependency from Rails

Other transitive updates (json, minitest) are patched versions with no impact.

Compatibility Assessment

Compatible - Security fix for XSS vulnerability. Not used in this codebase.

Test Coverage

N/A - Security patch in unused feature.

Confidence Rating

HIGH - Security fix for unused dependency. Safe to merge.

@mroderick mroderick merged commit e3028c6 into master Apr 12, 2026
16 checks passed
@mroderick mroderick deleted the dependabot/bundler/action_text-trix-2.1.18 branch April 12, 2026 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant