Bump simple_form from 4.1.0 to 5.0.0
Created by: dependabot[bot]
Bumps simple_form from 4.1.0 to 5.0.0.
Changelog
Sourced from simple_form's changelog.
5.0.0
Enhancements
- Set multiple attribute for grouped selects also. @ollym
- Removes or renames label classes. Abduvakilov
- Support to label custom classes for inline collections. @feliperenan
- Update bootstrap generator template to match v4.3.x. @m5o
- Allow "required" attribute in generated select elements of PriorityInput. @mcountis
Bug fix
- Do not call
#send
in form object to check whether the attribute is a file input. @tegonDeprecations
- The config
SimpleForm.file_methods
is deprecated and it has no effect. Simple Form now supports automatically discover of file inputs for the following Gems: activestorage, carrierwave, paperclip, refile and shrine. If you are using a custom method that is not from one of the supported Gems, please change your forms to pass the input type explicitly:<%= form.input :avatar, as: :file %>
See http://blog.plataformatec.com.br/2019/09/incorrect-access-control-in-simple-form-cve-2019-16676 for more information.
Commits
-
440ed5f
Include information about security issues in README.md and -
8c91bd7
Don't call#send
in form object to build file inputs -
62408e8
Removeruby-head
jobs -
69f4d46
Update jruby version -
bcc1197
Don't run specs with jruby 9.1 and Rails 6 -
8d56636
Fix full error message test on Rails 6 -
13d0341
Use different assertions for Rails 5 and 6 -
6f677ec
Don't run specs with Rails 6 and older rubies -
fc25ab4
Rails 6 and latest rubies on CI -
9d7921f
Merge pull request #1667 from olleolleolle/patch-1 - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot ignore this [patch|minor|major] version
will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.