Update dependency view_component to v4.15.0 #9

Open
renovate wants to merge 1 commit from renovate/view_component-4.x-lockfile into main
First-time contributor

This PR contains the following updates:

Package Change Age Confidence
view_component (source, changelog) 4.1.0 → 4.15.0 age confidence

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

viewcomponent/view_component (view_component)

v4.15.0: 4.15.0

Compare Source

  • Add experimental caching support, opt-in per component via include ViewComponent::ExperimentallyCacheable.

    Components have never participated in Rails' template digests, so a <% cache %> block wrapping render MyComponent.new was never invalidated when the component changed (#​234, open since 2020).

    Including the module registers the component with Rails' own ActionView::Digestor, so fragment caches are invalidated when the component's template, Ruby class, sidecar files, superclasses, child components, or rendered partials change. This includes components and partials rendered from inline templates and #call methods. Adding cache_on caches the component's own rendered output, optionally guarded by if:/unless:, and .cache_digest exposes the digest for use outside a request.

    class MessageComponent < ViewComponent::Base
      include ViewComponent::ExperimentallyCacheable
    
      cache_on :message, unless: -> { message.draft? }
    
      def initialize(message:)
        @&#8203;message = message
      end
    end
    

    This API is experimental and may change or be removed in a non-major release. It's shipping opt-in and per-component precisely so we can iterate on it in response to real-world use. Please try it and tell us what breaks, what's missing, and what feels wrong in #​234. We're especially interested in feedback on: whether cache_on is the right shape for declaring cache keys, how the feature behaves with slots and content blocks, and whether the # Template Dependency: escape hatch is sufficient for dynamic renders. See the caching guide for details and known caveats.

    This work builds directly on prior art from the community. The cache_on API and the case for component-local caching come from #​2126 by Reegan Viljoen. The approach of integrating with Rails' digest tree rather than reimplementing it comes from view_component-cache_digest by Godfrey Chan. The invalidation cases it's tested against were contributed by JWShuff and timburgan, drawing on view_component-fragment_caching by Patrick Arnett. The issue was opened and researched by ozzyaaron, pinzonjulian, and Derek Kniffin, and the digest workaround that surfaced the superclass gap came from cannikin and rnestler. Cache-key correctness issues (formats sharing an entry, positional nil collisions, conditional caching, and ignored cache_on blocks) were found and reported by Reegan Viljoen.

    Reegan Viljoen, Godfrey Chan, JWShuff, timburgan, Patrick Arnett, ozzyaaron, pinzonjulian, Derek Kniffin, cannikin, rnestler, Joel Hawksley

v4.14.0: 4.14.0

Compare Source

  • Freeze ReusedInstanceError::MESSAGE and update test_renders_component_with_asset_url to build a fresh AssetComponent per render, fixing CI regressions introduced by the GHSA-8qw7-6phv-7q6p remediation.

    Joel Hawksley

  • [Security] Fix incomplete remediation for CVE-2026-54497 (GHSA-8qw7-6phv-7q6p): reused ViewComponent instances could still leak with_content and renders_one/renders_many slot content from an earlier render into a later render because slot state and content set via with_content are populated by the caller before render_in runs and were not cleared by the previous per-render reset. Reinstate the ViewComponent::ReusedInstanceError guard that raises when a component instance is rendered more than once. Rebuild collection child components per render and dup collection spacer components before each render so that legitimate re-rendering of Collection/spacer objects continues to work.

    Yazan Balawneh, Cystack.ps

  • Update GitHub Actions workflows to use actions/checkout v7.

    Richard Macklin

v4.13.0: 4.13.0

Compare Source

  • Add support for Turbo-streaming ViewComponents.

    Ben Sheldon, Joel Hawksley

  • Reduce allocations and avoid redundant compiler work when rendering components and collections.

    Joel Hawksley

  • Stabilize rendering allocation tests with explicit warmups and exact expectations by Rails and Ruby.

    Joel Hawksley

  • Replace the custom memory allocation test helper with minitest-memory, preserving Ruby-version-specific allocation thresholds while improving failure diagnostics.

    Joel Hawksley

  • Add zizmor security analysis for GitHub Actions workflows to CI.

    Joel Hawksley

  • Remove the $PROGRAM_NAME version-printing line from version.rb so the file no longer reads a global variable (unshareable across Ractors). The version is still available via ViewComponent::VERSION::STRING.

    Joel Hawksley

  • Fix intermittent template compilation failures where line-number offsets and annotation stripping were decided when a template object was created instead of when it was compiled, so later changes to coverage or annotation settings produced off-by-one backtraces or blank output.

    Joel Hawksley

  • Freeze ViewComponent::VERSION::STRING so the version constant is immutable and Ractor-shareable.

    Joel Hawksley

  • Add audition Ractor-readiness checks to CI. Applied safe .freeze auto-fixes to string constants in ViewComponent::Errors and baselined existing findings so the gate fails only on new Ractor-isolation violations.

    Joel Hawksley

  • Update link to GOV.UK Components library in resources list to govuk-components.x-govuk.org

    Peter Yates

  • Fix NoMethodError: undefined method 'template_handler_extensions' when gathering sidecar templates on Rails main. Action View removed the ActionView::Template.template_handler_extensions method in newer versions; the compiler now reads the registered extensions through ActionView::Template::Handlers.extensions, which is the supported read-path API across all supported Rails versions (7.1+).

    Luiz Kowalski

v4.12.0: 4.12.0

Compare Source

  • Fix stale render context on reused component instances. A ViewComponent::Base instance memoized its controller, helpers, request, view context, lookup context, view flow, and requested format details on first render via ||=. Rendering the same instance a second time (intentionally or via aliasing) reused that stale context, which could leak data across requests, sessions, or users. #render_in now resets these ivars on every call so each render derives its context from the current view.

    Joel Hawksley

  • Fix HTML-safety bypass in around_render. ViewComponent::Base#around_render could return HTML-unsafe strings that bypassed the escaping applied to normal #call return values, creating an XSS risk. The vulnerability was amplified in ViewComponent::Collection#render_in, which joined per-item results and unconditionally marked the output html_safe. HTML-unsafe strings returned from around_render are now escaped (with a warning) and Collection#render_in now uses safe_join so unsafe per-item output is escaped instead of laundered into a SafeBuffer.
    Joel Hawksley

v4.11.0: 4.11.0

Compare Source

  • Update render_in signature to accept **_ for compatibility with Rails #​50623.

    Joel Hawksley

  • Fix translation scope resolution in nested lambda-backed slots. Relative t(".key") calls inside lambda-backed slots were resolving against an intermediate component's scope instead of the original partial's scope where the block was defined.

    Artin Boghosian

v4.10.0: 4.10.0

Compare Source

  • Fix NameError: uninitialized constant ViewComponent::SystemTestControllerNefariousPathError when booting in the test environment with eager_load = true.

    Joel Hawksley

  • Fix yielded content rendered at wrong location when using form helpers.

    Joel Hawksley, Markus

v4.9.0: 4.9.0

Compare Source

  • Fix path traversal vulnerability in ViewComponentsSystemTestController where sibling directories sharing a string prefix with the allowed temp directory could bypass the path containment check. The start_with? check has been replaced with a separator-aware prefix check, and nefarious path errors now return a 404 instead of an unhandled exception.

    Joel Hawksley

  • Fix preview route vulnerability where inherited methods on ViewComponent::Preview (such as render_with_template) could be invoked via the preview URL, allowing arbitrary internal Rails templates to be rendered with attacker-controlled locals and request parameters. render_args now raises AbstractController::ActionNotFound for any example not explicitly declared on the preview subclass.

    Joel Hawksley

  • Add yard-lint to CI.

    Joel Hawksley

v4.8.0: 4.8.0

Compare Source

  • Add compile.view_component ActiveSupport::Notifications event for eager compilation at boot time.

    Joel Hawksley, GitHub Copilot

v4.7.0: 4.7.0

Compare Source

  • Fix stale content cache when slots are accessed before render_in.

    Jared Armstrong

  • Add rubocop-view_component to resources.

    Andy Waite

  • Fix bug where inheritance of components with formatless templates improperly raised a NoMethodError.

    GitHub Copilot, Joel Hawksley, Cameron Dutro

v4.6.0: 4.6.0

Compare Source

  • Add view_identifier to the render.view_component instrumentation event payload, containing the path to the component's template file (e.g. app/components/my_component.html.erb). For components using inline render methods, view_identifier will be nil.

    GitHub Copilot

  • Replace deprecated require_dependency with require in preview loading.

    GitHub Copilot

  • Return html_safe empty string from render_in when render? is false.

    GitHub Copilot

v4.5.0: 4.5.0

Compare Source

  • Fix initialization ordering issue causing missing asset errors in Sprockets.

    Cameron Dutro

v4.4.0: 4.4.0

Compare Source

  • Fix segfaults when Ruby coverage is enabled.

    George Holborn, Joel Hawksley

  • Add protocol parameter to with_request_url test helper to enable testing with HTTPS protocol.

    Joel Hawksley

v4.3.0: 4.3.0

Compare Source

  • Fix load order issues for 3rd-party template handlers.

    Cameron Dutro

  • Fix segfault when Ruby coverage is enabled with Rails 8.1 ERB templates.

    George Holborn

  • Automatically merge dependabot PRs.

    Joel Hawksley

  • Use Ruby 4.0.0 in CI and dev.

    Joel Hawksley

v4.2.0: 4.2.0

Compare Source

  • Fix translation scope resolution in deeply nested component blocks (3+ levels). Translations called inside deeply nested slot blocks using renders_many/renders_one were incorrectly resolving to an intermediate component's scope instead of the partial's scope where the block was defined. The fix captures the virtual path at block definition time and restores it during block execution, ensuring translations always resolve relative to where the block was created regardless of nesting depth.

    Nathaniel Watts

  • Allow render_inline with Nokogiri::HTML5 to parse more arbitrary content including bare table content otherwise illegal fragments like <td>.

    Jonathan Rochkind

  • Remove known issue from docs as ActiveScaffold is now compatible with ViewComponent.

    David Löwenfels

  • Add test to document the current behavior for resolving relative translation keys within partial blocks. When rendering a partial, relative translation keys are resolved relative to the partial's own path rather than the caller’s path. This test ensures that this behavior remains consistent.

    Oussama Hilal

  • Allow I18n calls in render?.

    23tux

  • ViewComponent now works without rails and railties gems loaded, enabling compatibility with Bridgetown 2.0.

    Tom Lord

  • Capture partial block in the component's context, allowing access to the component instance inside the block.

    23tux

  • Add after_compile class method hook to enable extensions to run logic after component compilation.

    Jose Solás

  • Fix outdated reference to preview layout configuration in docs.

    Lucas Geron

  • Allow ruby-head CI job to fail without failing workflow.

    Hakan Ensari

  • Fix bug where error line numbers were incorrect in Rails 8.1.

    Joel Hawksley

  • Remove < 8.2 upper bound for activesupport and actionview dependencies.

    Hans Lemuet

  • Test compatibility with Herb/ReActionView.

    Joel Hawksley

  • Remove Who Uses ViewComponent section from docs.

    Joel Hawksley

v4.1.1: 4.1.1

Compare Source

  • Add Consultport to list of companies using ViewComponent.

    Sebastian Nepote

  • Resolve deprecation warning for ActiveSupport::Configurable.

    Simon Fish

  • Make ViewComponent::VERSION accessible to other gems by default.

    Hans Lemuet

  • Added Reinvented Hospitality to the list of companies using ViewComponent.

    Torgil Zechel


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [view_component](https://viewcomponent.org) ([source](https://github.com/viewcomponent/view_component), [changelog](https://github.com/ViewComponent/view_component/blob/main/docs/CHANGELOG.md)) | `4.1.0` → `4.15.0` | ![age](https://developer.mend.io/api/mc/badges/age/rubygems/view_component/4.15.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/rubygems/view_component/4.1.0/4.15.0?slim=true) | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the Dependency Dashboard for more information. --- ### Release Notes <details> <summary>viewcomponent/view_component (view_component)</summary> ### [`v4.15.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.15.0): 4.15.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.14.0...v4.15.0) - Add experimental caching support, opt-in per component via `include ViewComponent::ExperimentallyCacheable`. Components have never participated in Rails' template digests, so a `<% cache %>` block wrapping `render MyComponent.new` was never invalidated when the component changed ([#&#8203;234](https://github.com/ViewComponent/view_component/issues/234), open since 2020). Including the module registers the component with Rails' own `ActionView::Digestor`, so fragment caches are invalidated when the component's template, Ruby class, sidecar files, superclasses, child components, or rendered partials change. This includes components and partials rendered from inline templates and `#call` methods. Adding `cache_on` caches the component's own rendered output, optionally guarded by `if:`/`unless:`, and `.cache_digest` exposes the digest for use outside a request. ```ruby class MessageComponent < ViewComponent::Base include ViewComponent::ExperimentallyCacheable cache_on :message, unless: -> { message.draft? } def initialize(message:) @&#8203;message = message end end ``` **This API is experimental and may change or be removed in a non-major release.** It's shipping opt-in and per-component precisely so we can iterate on it in response to real-world use. **Please try it and tell us what breaks, what's missing, and what feels wrong in [#&#8203;234](https://github.com/ViewComponent/view_component/issues/234).** We're especially interested in feedback on: whether `cache_on` is the right shape for declaring cache keys, how the feature behaves with slots and content blocks, and whether the `# Template Dependency:` escape hatch is sufficient for dynamic renders. See [the caching guide](https://viewcomponent.org/guide/caching.html) for details and known caveats. This work builds directly on prior art from the community. The `cache_on` API and the case for component-local caching come from [#&#8203;2126](https://github.com/ViewComponent/view_component/pull/2126) by *Reegan Viljoen*. The approach of integrating with Rails' digest tree rather than reimplementing it comes from [`view_component-cache_digest`](https://github.com/tildeio/view_component-cache_digest) by *Godfrey Chan*. The invalidation cases it's tested against were contributed by *JWShuff* and *timburgan*, drawing on [`view_component-fragment_caching`](https://github.com/patrickarnett/view_component-fragment_caching) by *Patrick Arnett*. The issue was opened and researched by *ozzyaaron*, *pinzonjulian*, and *Derek Kniffin*, and the digest workaround that surfaced the superclass gap came from *cannikin* and *rnestler*. Cache-key correctness issues (formats sharing an entry, positional `nil` collisions, conditional caching, and ignored `cache_on` blocks) were found and reported by *Reegan Viljoen*. *Reegan Viljoen*, *Godfrey Chan*, *JWShuff*, *timburgan*, *Patrick Arnett*, *ozzyaaron*, *pinzonjulian*, *Derek Kniffin*, *cannikin*, *rnestler*, *Joel Hawksley* ### [`v4.14.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.14.0): 4.14.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.13.0...v4.14.0) - Freeze `ReusedInstanceError::MESSAGE` and update `test_renders_component_with_asset_url` to build a fresh `AssetComponent` per render, fixing CI regressions introduced by the GHSA-8qw7-6phv-7q6p remediation. *Joel Hawksley* - \[Security] Fix incomplete remediation for CVE-2026-54497 (GHSA-8qw7-6phv-7q6p): reused ViewComponent instances could still leak `with_content` and `renders_one`/`renders_many` slot content from an earlier render into a later render because slot state and content set via `with_content` are populated by the caller before `render_in` runs and were not cleared by the previous per-render reset. Reinstate the `ViewComponent::ReusedInstanceError` guard that raises when a component instance is rendered more than once. Rebuild collection child components per render and dup collection spacer components before each render so that legitimate re-rendering of `Collection`/spacer objects continues to work. *Yazan Balawneh, Cystack.ps* - Update GitHub Actions workflows to use `actions/checkout` v7. *Richard Macklin* ### [`v4.13.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.13.0): 4.13.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.12.0...v4.13.0) - Add support for Turbo-streaming ViewComponents. *Ben Sheldon*, *Joel Hawksley* - Reduce allocations and avoid redundant compiler work when rendering components and collections. *Joel Hawksley* - Stabilize rendering allocation tests with explicit warmups and exact expectations by Rails and Ruby. *Joel Hawksley* - Replace the custom memory allocation test helper with `minitest-memory`, preserving Ruby-version-specific allocation thresholds while improving failure diagnostics. *Joel Hawksley* - Add zizmor security analysis for GitHub Actions workflows to CI. *Joel Hawksley* - Remove the `$PROGRAM_NAME` version-printing line from `version.rb` so the file no longer reads a global variable (unshareable across Ractors). The version is still available via `ViewComponent::VERSION::STRING`. *Joel Hawksley* - Fix intermittent template compilation failures where line-number offsets and annotation stripping were decided when a template object was created instead of when it was compiled, so later changes to coverage or annotation settings produced off-by-one backtraces or blank output. *Joel Hawksley* - Freeze `ViewComponent::VERSION::STRING` so the version constant is immutable and Ractor-shareable. *Joel Hawksley* - Add [audition](https://github.com/yaroslav/audition) Ractor-readiness checks to CI. Applied safe `.freeze` auto-fixes to string constants in `ViewComponent::Errors` and baselined existing findings so the gate fails only on new Ractor-isolation violations. *Joel Hawksley* - Update link to GOV.UK Components library in resources list to govuk-components.x-govuk.org *Peter Yates* - Fix `NoMethodError: undefined method 'template_handler_extensions'` when gathering sidecar templates on Rails main. Action View removed the `ActionView::Template.template_handler_extensions` method in newer versions; the compiler now reads the registered extensions through `ActionView::Template::Handlers.extensions`, which is the supported read-path API across all supported Rails versions (7.1+). *Luiz Kowalski* ### [`v4.12.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.12.0): 4.12.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.11.0...v4.12.0) - Fix stale render context on reused component instances. A `ViewComponent::Base` instance memoized its controller, helpers, request, view context, lookup context, view flow, and requested format details on first render via `||=`. Rendering the same instance a second time (intentionally or via aliasing) reused that stale context, which could leak data across requests, sessions, or users. `#render_in` now resets these ivars on every call so each render derives its context from the current view. *Joel Hawksley* - Fix HTML-safety bypass in `around_render`. `ViewComponent::Base#around_render` could return HTML-unsafe strings that bypassed the escaping applied to normal `#call` return values, creating an XSS risk. The vulnerability was amplified in `ViewComponent::Collection#render_in`, which joined per-item results and unconditionally marked the output `html_safe`. HTML-unsafe strings returned from `around_render` are now escaped (with a warning) and `Collection#render_in` now uses `safe_join` so unsafe per-item output is escaped instead of laundered into a `SafeBuffer`. *Joel Hawksley* ### [`v4.11.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.11.0): 4.11.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.10.0...v4.11.0) - Update `render_in` signature to accept `**_` for compatibility with Rails [#&#8203;50623](https://github.com/rails/rails/pull/50623). *Joel Hawksley* - Fix translation scope resolution in nested lambda-backed slots. Relative `t(".key")` calls inside lambda-backed slots were resolving against an intermediate component's scope instead of the original partial's scope where the block was defined. *Artin Boghosian* ### [`v4.10.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.10.0): 4.10.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.9.0...v4.10.0) - Fix `NameError: uninitialized constant ViewComponent::SystemTestControllerNefariousPathError` when booting in the test environment with `eager_load = true`. *Joel Hawksley* - Fix yielded content rendered at wrong location when using form helpers. *Joel Hawksley*, *Markus* ### [`v4.9.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.9.0): 4.9.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.8.0...v4.9.0) - Fix path traversal vulnerability in `ViewComponentsSystemTestController` where sibling directories sharing a string prefix with the allowed temp directory could bypass the path containment check. The `start_with?` check has been replaced with a separator-aware prefix check, and nefarious path errors now return a 404 instead of an unhandled exception. *Joel Hawksley* - Fix preview route vulnerability where inherited methods on `ViewComponent::Preview` (such as `render_with_template`) could be invoked via the preview URL, allowing arbitrary internal Rails templates to be rendered with attacker-controlled locals and request parameters. `render_args` now raises `AbstractController::ActionNotFound` for any example not explicitly declared on the preview subclass. *Joel Hawksley* - Add `yard-lint` to CI. *Joel Hawksley* ### [`v4.8.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.8.0): 4.8.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.7.0...v4.8.0) - Add `compile.view_component` ActiveSupport::Notifications event for eager compilation at boot time. *Joel Hawksley*, *GitHub Copilot* ### [`v4.7.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.7.0): 4.7.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.6.0...v4.7.0) - Fix stale content cache when slots are accessed before `render_in`. *Jared Armstrong* - Add rubocop-view\_component to resources. *Andy Waite* - Fix bug where inheritance of components with formatless templates improperly raised a NoMethodError. *GitHub Copilot*, *Joel Hawksley*, *Cameron Dutro* ### [`v4.6.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.6.0): 4.6.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.5.0...v4.6.0) - Add `view_identifier` to the `render.view_component` instrumentation event payload, containing the path to the component's template file (e.g. `app/components/my_component.html.erb`). For components using inline render methods, `view_identifier` will be `nil`. *GitHub Copilot* - Replace deprecated `require_dependency` with `require` in preview loading. *GitHub Copilot* - Return `html_safe` empty string from `render_in` when `render?` is false. *GitHub Copilot* ### [`v4.5.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.5.0): 4.5.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.4.0...v4.5.0) - Fix initialization ordering issue causing missing asset errors in Sprockets. *Cameron Dutro* ### [`v4.4.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.4.0): 4.4.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.3.0...v4.4.0) - Fix segfaults when Ruby coverage is enabled. *George Holborn*, *Joel Hawksley* - Add `protocol` parameter to `with_request_url` test helper to enable testing with HTTPS protocol. *Joel Hawksley* ### [`v4.3.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.3.0): 4.3.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.2.0...v4.3.0) - Fix load order issues for 3rd-party template handlers. *Cameron Dutro* - Fix segfault when Ruby coverage is enabled with Rails 8.1 ERB templates. *George Holborn* - Automatically merge dependabot PRs. *Joel Hawksley* - Use Ruby 4.0.0 in CI and dev. *Joel Hawksley* ### [`v4.2.0`](https://github.com/ViewComponent/view_component/releases/tag/v4.2.0): 4.2.0 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.1.1...v4.2.0) - Fix translation scope resolution in deeply nested component blocks (3+ levels). Translations called inside deeply nested slot blocks using `renders_many`/`renders_one` were incorrectly resolving to an intermediate component's scope instead of the partial's scope where the block was defined. The fix captures the virtual path at block definition time and restores it during block execution, ensuring translations always resolve relative to where the block was created regardless of nesting depth. *Nathaniel Watts* - Allow `render_inline` with Nokogiri::HTML5 to parse more arbitrary content including bare table content otherwise illegal fragments like `<td>`. *Jonathan Rochkind* - Remove known issue from docs as ActiveScaffold is [now compatible](https://github.com/activescaffold/active_scaffold/pull/743) with ViewComponent. *David Löwenfels* - Add test to document the current behavior for resolving relative translation keys within partial blocks. When rendering a partial, relative translation keys are resolved relative to the partial's own path rather than the caller’s path. This test ensures that this behavior remains consistent. *Oussama Hilal* - Allow I18n calls in `render?`. *23tux* - ViewComponent now works without `rails` and `railties` gems loaded, enabling compatibility with Bridgetown 2.0. *Tom Lord* - Capture partial block in the component's context, allowing access to the component instance inside the block. *23tux* - Add `after_compile` class method hook to enable extensions to run logic after component compilation. *Jose Solás* - Fix outdated reference to preview layout configuration in docs. *Lucas Geron* - Allow ruby-head CI job to fail without failing workflow. *Hakan Ensari* - Fix bug where error line numbers were incorrect in Rails 8.1. *Joel Hawksley* - Remove `< 8.2` upper bound for `activesupport` and `actionview` dependencies. *Hans Lemuet* - Test compatibility with Herb/ReActionView. *Joel Hawksley* - Remove Who Uses ViewComponent section from docs. *Joel Hawksley* ### [`v4.1.1`](https://github.com/ViewComponent/view_component/releases/tag/v4.1.1): 4.1.1 [Compare Source](https://github.com/viewcomponent/view_component/compare/v4.1.0...v4.1.1) - Add Consultport to list of companies using ViewComponent. *Sebastian Nepote* - Resolve deprecation warning for `ActiveSupport::Configurable`. *Simon Fish* - Make `ViewComponent::VERSION` accessible to other gems by default. *Hans Lemuet* - Added Reinvented Hospitality to the list of companies using ViewComponent. *Torgil Zechel* </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4yLjAiLCJ1cGRhdGVkSW5WZXIiOiI0Mi43MS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Update dependency view_component to v4.1.1
Some checks failed
build.yml / Update dependency view_component to v4.1.1 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.1.1 (push) Failing after 0s
build.yml / Update dependency view_component to v4.1.1 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.1.1 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
6df221ae26
renovate force-pushed renovate/view_component-4.x-lockfile from 6df221ae26
Some checks failed
build.yml / Update dependency view_component to v4.1.1 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.1.1 (push) Failing after 0s
build.yml / Update dependency view_component to v4.1.1 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.1.1 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 2143e9e61a
Some checks failed
build.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-01-10 00:01:37 +00:00
Compare
renovate changed title from Update dependency view_component to v4.1.1 to Update dependency view_component to v4.2.0 2026-01-10 00:01:39 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 2143e9e61a
Some checks failed
build.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 437d4311fc
Some checks failed
build.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-01-12 00:01:42 +00:00
Compare
renovate force-pushed renovate/view_component-4.x-lockfile from 437d4311fc
Some checks failed
build.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.2.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 26d0e7e5a6
Some checks failed
build.yml / Update dependency view_component to v4.3.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.3.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.3.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.3.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Waiting to run
2026-02-12 00:01:54 +00:00
Compare
renovate changed title from Update dependency view_component to v4.2.0 to Update dependency view_component to v4.3.0 2026-02-12 00:01:57 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 26d0e7e5a6
Some checks failed
build.yml / Update dependency view_component to v4.3.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.3.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.3.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.3.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Waiting to run
to 0032fdff83
Some checks failed
build.yml / Update dependency view_component to v4.4.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.4.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.4.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.4.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-02-14 00:01:31 +00:00
Compare
renovate changed title from Update dependency view_component to v4.3.0 to Update dependency view_component to v4.4.0 2026-02-14 00:01:35 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 0032fdff83
Some checks failed
build.yml / Update dependency view_component to v4.4.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.4.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.4.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.4.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to a2a8d5ccfb
Some checks failed
build.yml / Update dependency view_component to v4.5.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.5.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.5.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.5.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-02-27 00:01:37 +00:00
Compare
renovate changed title from Update dependency view_component to v4.4.0 to Update dependency view_component to v4.5.0 2026-02-27 00:01:40 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from a2a8d5ccfb
Some checks failed
build.yml / Update dependency view_component to v4.5.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.5.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.5.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.5.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 1dd9f08439
Some checks failed
build.yml / Update dependency view_component to v4.6.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.6.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.6.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.6.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-03-31 00:01:41 +00:00
Compare
renovate changed title from Update dependency view_component to v4.5.0 to Update dependency view_component to v4.6.0 2026-03-31 00:01:44 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 1dd9f08439
Some checks failed
build.yml / Update dependency view_component to v4.6.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.6.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.6.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.6.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to d1a078749c
Some checks failed
build.yml / Update dependency view_component to v4.7.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.7.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.7.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.7.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-04-18 00:01:43 +00:00
Compare
renovate changed title from Update dependency view_component to v4.6.0 to Update dependency view_component to v4.7.0 2026-04-18 00:01:46 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from d1a078749c
Some checks failed
build.yml / Update dependency view_component to v4.7.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.7.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.7.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.7.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 5db33e798b
Some checks failed
build.yml / Update dependency view_component to v4.8.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.8.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.8.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.8.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-04-23 00:01:52 +00:00
Compare
renovate changed title from Update dependency view_component to v4.7.0 to Update dependency view_component to v4.8.0 2026-04-23 00:01:55 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 5db33e798b
Some checks failed
build.yml / Update dependency view_component to v4.8.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.8.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.8.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.8.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 0568e1e1c6
Some checks failed
build.yml / Update dependency view_component to v4.9.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.9.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.9.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.9.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-05-06 00:01:38 +00:00
Compare
renovate changed title from Update dependency view_component to v4.8.0 to Update dependency view_component to v4.9.0 2026-05-06 00:01:41 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 0568e1e1c6
Some checks failed
build.yml / Update dependency view_component to v4.9.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.9.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.9.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.9.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 79dc38980c
Some checks failed
build.yml / Update dependency view_component to v4.10.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.10.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.10.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.10.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-05-12 00:01:59 +00:00
Compare
renovate changed title from Update dependency view_component to v4.9.0 to Update dependency view_component to v4.10.0 2026-05-12 00:02:03 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 79dc38980c
Some checks failed
build.yml / Update dependency view_component to v4.10.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.10.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.10.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.10.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 82be3549d2
Some checks failed
build.yml / Update dependency view_component to v4.11.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.11.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.11.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.11.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
2026-05-19 00:01:17 +00:00
Compare
renovate changed title from Update dependency view_component to v4.10.0 to Update dependency view_component to v4.11.0 2026-05-19 00:01:21 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 82be3549d2
Some checks failed
build.yml / Update dependency view_component to v4.11.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.11.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.11.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.11.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Has been cancelled
to 354dcf963d
Some checks failed
build.yml / Update dependency view_component to v4.12.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.12.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.12.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.12.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Failing after 2s
2026-06-05 00:02:05 +00:00
Compare
renovate changed title from Update dependency view_component to v4.11.0 to Update dependency view_component to v4.12.0 2026-06-05 00:02:10 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 354dcf963d
Some checks failed
build.yml / Update dependency view_component to v4.12.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.12.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.12.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.12.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Failing after 2s
to 575f44e93d
Some checks failed
build.yml / Update dependency view_component to v4.14.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.14.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.14.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.14.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Failing after 2s
2026-08-25 00:01:37 +00:00
Compare
renovate changed title from Update dependency view_component to v4.12.0 to Update dependency view_component to v4.14.0 2026-08-25 00:01:42 +00:00
renovate force-pushed renovate/view_component-4.x-lockfile from 575f44e93d
Some checks failed
build.yml / Update dependency view_component to v4.14.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.14.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.14.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.14.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Failing after 2s
to 2f7e2cb4d1
Some checks failed
build.yml / Update dependency view_component to v4.15.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.15.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.15.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.15.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Failing after 3s
2026-08-26 00:01:51 +00:00
Compare
renovate changed title from Update dependency view_component to v4.14.0 to Update dependency view_component to v4.15.0 2026-08-26 00:01:56 +00:00
Some checks failed
build.yml / Update dependency view_component to v4.15.0 (push) Failing after 0s
deploy.yml / Update dependency view_component to v4.15.0 (push) Failing after 0s
build.yml / Update dependency view_component to v4.15.0 (pull_request) Failing after 0s
deploy.yml / Update dependency view_component to v4.15.0 (pull_request) Failing after 0s
Release Drafter / update_release_draft (pull_request) Failing after 3s
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/view_component-4.x-lockfile:renovate/view_component-4.x-lockfile
git switch renovate/view_component-4.x-lockfile

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/view_component-4.x-lockfile
git switch renovate/view_component-4.x-lockfile
git rebase main
git switch main
git merge --ff-only renovate/view_component-4.x-lockfile
git switch renovate/view_component-4.x-lockfile
git rebase main
git switch main
git merge --no-ff renovate/view_component-4.x-lockfile
git switch main
git merge --squash renovate/view_component-4.x-lockfile
git switch main
git merge --ff-only renovate/view_component-4.x-lockfile
git switch main
git merge renovate/view_component-4.x-lockfile
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
hobbypunk/discord-santa!9
No description provided.