Skip to content

Bump thruster from 0.1.16 to 0.1.21#89

Merged
JuanVqz merged 1 commit into
mainfrom
dependabot/bundler/thruster-0.1.21
May 25, 2026
Merged

Bump thruster from 0.1.16 to 0.1.21#89
JuanVqz merged 1 commit into
mainfrom
dependabot/bundler/thruster-0.1.21

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 21, 2026

Bumps thruster from 0.1.16 to 0.1.21.

Changelog

Sourced from thruster's changelog.

v0.1.21 / 2026-05-17

  • Build with Go 1.26.3

v0.1.20 / 2026-03-25

  • Only redirect HTTP->HTTPS for policy-allowed hosts

v0.1.19 / 2026-03-06

  • Build with Go 1.26.1

v0.1.18 / 2026-02-02

  • Return correct exit code when terminated with signal (#110)
  • Build with Go 1.25.6

v0.1.17 / 2025-12-16

  • Mitigate BREACH attacks with random jitter and optional compression guard (#102)
Commits
  • aaeecd4 Update version & changelog
  • 4f1a021 Merge pull request #127 from rvanlieshout/bump-go-1.26.2
  • f9161a2 Build with Go 1.26.3
  • 53da229 Build with Go 1.26.2
  • bddb1d8 Merge pull request #120 from basecamp/check-tls-domain-for-redirects
  • 186b8f5 Only redirect HTTP->HTTPS for policy-allowed hosts
  • d925847 Address PR review feedback from Copilot
  • b090a2e Validate Host header against TLS domains in HTTP→HTTPS redirect
  • b47fc5b ci: harden GitHub Actions workflows (#117)
  • e17d3ee Go 1.26.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [thruster](https://github.com/basecamp/thruster) from 0.1.16 to 0.1.21.
- [Changelog](https://github.com/basecamp/thruster/blob/main/CHANGELOG.md)
- [Commits](basecamp/thruster@v0.1.16...v0.1.21)

---
updated-dependencies:
- dependency-name: thruster
  dependency-version: 0.1.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels May 21, 2026
@JuanVqz JuanVqz merged commit 35d9fef into main May 25, 2026
4 checks passed
@dependabot dependabot Bot deleted the dependabot/bundler/thruster-0.1.21 branch May 25, 2026 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant