Update dependency view_component to v4.15.0 #9
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/view_component-4.x-lockfile"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
4.1.0→4.15.0Release Notes
viewcomponent/view_component (view_component)
v4.15.0: 4.15.0Compare Source
Add experimental caching support, opt-in per component via
include ViewComponent::ExperimentallyCacheable.Components have never participated in Rails' template digests, so a
<% cache %>block wrappingrender MyComponent.newwas never invalidated when the component changed (#234, open since 2020).Including the module registers the component with Rails' own
ActionView::Digestor, so fragment caches are invalidated when the component's template, Ruby class, sidecar files, superclasses, child components, or rendered partials change. This includes components and partials rendered from inline templates and#callmethods. Addingcache_oncaches the component's own rendered output, optionally guarded byif:/unless:, and.cache_digestexposes the digest for use outside a request.This API is experimental and may change or be removed in a non-major release. It's shipping opt-in and per-component precisely so we can iterate on it in response to real-world use. Please try it and tell us what breaks, what's missing, and what feels wrong in #234. We're especially interested in feedback on: whether
cache_onis the right shape for declaring cache keys, how the feature behaves with slots and content blocks, and whether the# Template Dependency:escape hatch is sufficient for dynamic renders. See the caching guide for details and known caveats.This work builds directly on prior art from the community. The
cache_onAPI and the case for component-local caching come from #2126 by Reegan Viljoen. The approach of integrating with Rails' digest tree rather than reimplementing it comes fromview_component-cache_digestby Godfrey Chan. The invalidation cases it's tested against were contributed by JWShuff and timburgan, drawing onview_component-fragment_cachingby Patrick Arnett. The issue was opened and researched by ozzyaaron, pinzonjulian, and Derek Kniffin, and the digest workaround that surfaced the superclass gap came from cannikin and rnestler. Cache-key correctness issues (formats sharing an entry, positionalnilcollisions, conditional caching, and ignoredcache_onblocks) were found and reported by Reegan Viljoen.Reegan Viljoen, Godfrey Chan, JWShuff, timburgan, Patrick Arnett, ozzyaaron, pinzonjulian, Derek Kniffin, cannikin, rnestler, Joel Hawksley
v4.14.0: 4.14.0Compare Source
Freeze
ReusedInstanceError::MESSAGEand updatetest_renders_component_with_asset_urlto build a freshAssetComponentper render, fixing CI regressions introduced by the GHSA-8qw7-6phv-7q6p remediation.Joel Hawksley
[Security] Fix incomplete remediation for CVE-2026-54497 (GHSA-8qw7-6phv-7q6p): reused ViewComponent instances could still leak
with_contentandrenders_one/renders_manyslot content from an earlier render into a later render because slot state and content set viawith_contentare populated by the caller beforerender_inruns and were not cleared by the previous per-render reset. Reinstate theViewComponent::ReusedInstanceErrorguard that raises when a component instance is rendered more than once. Rebuild collection child components per render and dup collection spacer components before each render so that legitimate re-rendering ofCollection/spacer objects continues to work.Yazan Balawneh, Cystack.ps
Update GitHub Actions workflows to use
actions/checkoutv7.Richard Macklin
v4.13.0: 4.13.0Compare Source
Add support for Turbo-streaming ViewComponents.
Ben Sheldon, Joel Hawksley
Reduce allocations and avoid redundant compiler work when rendering components and collections.
Joel Hawksley
Stabilize rendering allocation tests with explicit warmups and exact expectations by Rails and Ruby.
Joel Hawksley
Replace the custom memory allocation test helper with
minitest-memory, preserving Ruby-version-specific allocation thresholds while improving failure diagnostics.Joel Hawksley
Add zizmor security analysis for GitHub Actions workflows to CI.
Joel Hawksley
Remove the
$PROGRAM_NAMEversion-printing line fromversion.rbso the file no longer reads a global variable (unshareable across Ractors). The version is still available viaViewComponent::VERSION::STRING.Joel Hawksley
Fix intermittent template compilation failures where line-number offsets and annotation stripping were decided when a template object was created instead of when it was compiled, so later changes to coverage or annotation settings produced off-by-one backtraces or blank output.
Joel Hawksley
Freeze
ViewComponent::VERSION::STRINGso the version constant is immutable and Ractor-shareable.Joel Hawksley
Add audition Ractor-readiness checks to CI. Applied safe
.freezeauto-fixes to string constants inViewComponent::Errorsand baselined existing findings so the gate fails only on new Ractor-isolation violations.Joel Hawksley
Update link to GOV.UK Components library in resources list to govuk-components.x-govuk.org
Peter Yates
Fix
NoMethodError: undefined method 'template_handler_extensions'when gathering sidecar templates on Rails main. Action View removed theActionView::Template.template_handler_extensionsmethod in newer versions; the compiler now reads the registered extensions throughActionView::Template::Handlers.extensions, which is the supported read-path API across all supported Rails versions (7.1+).Luiz Kowalski
v4.12.0: 4.12.0Compare Source
Fix stale render context on reused component instances. A
ViewComponent::Baseinstance memoized its controller, helpers, request, view context, lookup context, view flow, and requested format details on first render via||=. Rendering the same instance a second time (intentionally or via aliasing) reused that stale context, which could leak data across requests, sessions, or users.#render_innow resets these ivars on every call so each render derives its context from the current view.Joel Hawksley
Fix HTML-safety bypass in
around_render.ViewComponent::Base#around_rendercould return HTML-unsafe strings that bypassed the escaping applied to normal#callreturn values, creating an XSS risk. The vulnerability was amplified inViewComponent::Collection#render_in, which joined per-item results and unconditionally marked the outputhtml_safe. HTML-unsafe strings returned fromaround_renderare now escaped (with a warning) andCollection#render_innow usessafe_joinso unsafe per-item output is escaped instead of laundered into aSafeBuffer.Joel Hawksley
v4.11.0: 4.11.0Compare Source
Update
render_insignature to accept**_for compatibility with Rails #50623.Joel Hawksley
Fix translation scope resolution in nested lambda-backed slots. Relative
t(".key")calls inside lambda-backed slots were resolving against an intermediate component's scope instead of the original partial's scope where the block was defined.Artin Boghosian
v4.10.0: 4.10.0Compare Source
Fix
NameError: uninitialized constant ViewComponent::SystemTestControllerNefariousPathErrorwhen booting in the test environment witheager_load = true.Joel Hawksley
Fix yielded content rendered at wrong location when using form helpers.
Joel Hawksley, Markus
v4.9.0: 4.9.0Compare Source
Fix path traversal vulnerability in
ViewComponentsSystemTestControllerwhere sibling directories sharing a string prefix with the allowed temp directory could bypass the path containment check. Thestart_with?check has been replaced with a separator-aware prefix check, and nefarious path errors now return a 404 instead of an unhandled exception.Joel Hawksley
Fix preview route vulnerability where inherited methods on
ViewComponent::Preview(such asrender_with_template) could be invoked via the preview URL, allowing arbitrary internal Rails templates to be rendered with attacker-controlled locals and request parameters.render_argsnow raisesAbstractController::ActionNotFoundfor any example not explicitly declared on the preview subclass.Joel Hawksley
Add
yard-lintto CI.Joel Hawksley
v4.8.0: 4.8.0Compare Source
Add
compile.view_componentActiveSupport::Notifications event for eager compilation at boot time.Joel Hawksley, GitHub Copilot
v4.7.0: 4.7.0Compare Source
Fix stale content cache when slots are accessed before
render_in.Jared Armstrong
Add rubocop-view_component to resources.
Andy Waite
Fix bug where inheritance of components with formatless templates improperly raised a NoMethodError.
GitHub Copilot, Joel Hawksley, Cameron Dutro
v4.6.0: 4.6.0Compare Source
Add
view_identifierto therender.view_componentinstrumentation event payload, containing the path to the component's template file (e.g.app/components/my_component.html.erb). For components using inline render methods,view_identifierwill benil.GitHub Copilot
Replace deprecated
require_dependencywithrequirein preview loading.GitHub Copilot
Return
html_safeempty string fromrender_inwhenrender?is false.GitHub Copilot
v4.5.0: 4.5.0Compare Source
Fix initialization ordering issue causing missing asset errors in Sprockets.
Cameron Dutro
v4.4.0: 4.4.0Compare Source
Fix segfaults when Ruby coverage is enabled.
George Holborn, Joel Hawksley
Add
protocolparameter towith_request_urltest helper to enable testing with HTTPS protocol.Joel Hawksley
v4.3.0: 4.3.0Compare Source
Fix load order issues for 3rd-party template handlers.
Cameron Dutro
Fix segfault when Ruby coverage is enabled with Rails 8.1 ERB templates.
George Holborn
Automatically merge dependabot PRs.
Joel Hawksley
Use Ruby 4.0.0 in CI and dev.
Joel Hawksley
v4.2.0: 4.2.0Compare Source
Fix translation scope resolution in deeply nested component blocks (3+ levels). Translations called inside deeply nested slot blocks using
renders_many/renders_onewere incorrectly resolving to an intermediate component's scope instead of the partial's scope where the block was defined. The fix captures the virtual path at block definition time and restores it during block execution, ensuring translations always resolve relative to where the block was created regardless of nesting depth.Nathaniel Watts
Allow
render_inlinewith Nokogiri::HTML5 to parse more arbitrary content including bare table content otherwise illegal fragments like<td>.Jonathan Rochkind
Remove known issue from docs as ActiveScaffold is now compatible with ViewComponent.
David Löwenfels
Add test to document the current behavior for resolving relative translation keys within partial blocks. When rendering a partial, relative translation keys are resolved relative to the partial's own path rather than the caller’s path. This test ensures that this behavior remains consistent.
Oussama Hilal
Allow I18n calls in
render?.23tux
ViewComponent now works without
railsandrailtiesgems loaded, enabling compatibility with Bridgetown 2.0.Tom Lord
Capture partial block in the component's context, allowing access to the component instance inside the block.
23tux
Add
after_compileclass method hook to enable extensions to run logic after component compilation.Jose Solás
Fix outdated reference to preview layout configuration in docs.
Lucas Geron
Allow ruby-head CI job to fail without failing workflow.
Hakan Ensari
Fix bug where error line numbers were incorrect in Rails 8.1.
Joel Hawksley
Remove
< 8.2upper bound foractivesupportandactionviewdependencies.Hans Lemuet
Test compatibility with Herb/ReActionView.
Joel Hawksley
Remove Who Uses ViewComponent section from docs.
Joel Hawksley
v4.1.1: 4.1.1Compare Source
Add Consultport to list of companies using ViewComponent.
Sebastian Nepote
Resolve deprecation warning for
ActiveSupport::Configurable.Simon Fish
Make
ViewComponent::VERSIONaccessible to other gems by default.Hans Lemuet
Added Reinvented Hospitality to the list of companies using ViewComponent.
Torgil Zechel
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
6df221ae262143e9e61aUpdate dependency view_component to v4.1.1to Update dependency view_component to v4.2.02143e9e61a437d4311fc437d4311fc26d0e7e5a6Update dependency view_component to v4.2.0to Update dependency view_component to v4.3.026d0e7e5a60032fdff83Update dependency view_component to v4.3.0to Update dependency view_component to v4.4.00032fdff83a2a8d5ccfbUpdate dependency view_component to v4.4.0to Update dependency view_component to v4.5.0a2a8d5ccfb1dd9f08439Update dependency view_component to v4.5.0to Update dependency view_component to v4.6.01dd9f08439d1a078749cUpdate dependency view_component to v4.6.0to Update dependency view_component to v4.7.0d1a078749c5db33e798bUpdate dependency view_component to v4.7.0to Update dependency view_component to v4.8.05db33e798b0568e1e1c6Update dependency view_component to v4.8.0to Update dependency view_component to v4.9.00568e1e1c679dc38980cUpdate dependency view_component to v4.9.0to Update dependency view_component to v4.10.079dc38980c82be3549d2Update dependency view_component to v4.10.0to Update dependency view_component to v4.11.082be3549d2354dcf963dUpdate dependency view_component to v4.11.0to Update dependency view_component to v4.12.0354dcf963d575f44e93dUpdate dependency view_component to v4.12.0to Update dependency view_component to v4.14.0575f44e93d2f7e2cb4d1Update dependency view_component to v4.14.0to Update dependency view_component to v4.15.0View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.