Skip to content

chore(deps): bump fastlane from 2.238.0 to 2.239.0 - #1078

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/fastlane-2.239.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/fastlane-2.239.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps fastlane from 2.238.0 to 2.239.0.

Release notes

Sourced from fastlane's releases.

2.239.0 Improvements

  • [supply] list google play releases (#30000) via Tim Shedor (@​tshedor)
  • [sigh] Fix duplicate prefix in application-identifier entitlement during resign (#30169) via Shubhransh Gupta (@​shubhransh-gupta)
  • [Ruby] Ruby 3.1 is now the minimum (dropping Ruby 3.0) (#30120) via Connor Tumbleson (@​iBotPeaches)
  • [deliver/pilot] support app coverage files (#30153) via Connor Tumbleson (@​iBotPeaches)
  • [match] prevent leaking keys if invalid usage (#30161) via Connor Tumbleson (@​iBotPeaches)
  • [meta] set pr template to drop reference to CircleCI (#30162) via Connor Tumbleson (@​iBotPeaches)
  • [deliver] prevent duplicate image uploads (#30150) via Connor Tumbleson (@​iBotPeaches)
  • [match] Remove command on failure to prevent secret exposure for git storage. (#30165) via Aleksandr B (@​sozzjilly)
  • [pem] Add support for VoIP Services push certificates (#30166) via Rafael da Rosa Ferreira (@​Rafinha-rf)
  • harden: detected non-static command inside system in... (#30147) via Anupam Mediratta (@​anupamme)
  • [changelog_from_git_commits] Add optional argument to filter commits. (#14441) via Juan A. Romero (@​rukano)
  • [sh_helper] fix output stripping - invalid byte sequence in UTF-8 (ArgumentError) (#20539) via Wendy Liga (@​wendyliga)
  • [ci] move release workflows to Ruby 3.4 (#30155) via Connor Tumbleson (@​iBotPeaches)
  • [gems] move to json 2.21.x (#30156) via Connor Tumbleson (@​iBotPeaches)
Commits
  • 280c8e8 Version bump to 2.239.0 (#30173)
  • 0d78335 [supply] list google play releases + upgrade google_apis (#30000)
  • c1df394 [sigh] Fix duplicate prefix in application-identifier entitlement during resi...
  • 4a21dfd [Ruby] Ruby 3.1 is now the minimum (dropping Ruby 3.0) (#30120)
  • 92c8d32 [deliver/pilot] support app coverage files (#30153)
  • e905e87 [match] prevent leaking keys if invalid usage (#30161)
  • 5775292 [meta] set pr template to drop reference to CircleCI (#30162)
  • fdc4332 [deliver] prevent duplicate image uploads (#30150)
  • 8e08a6a [match] Remove command on failure to prevent secret exposure for git storage....
  • 1b9f1f8 [pem] Add support for VoIP Services push certificates (#30166)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Medium Risk
Touches the iOS release/signing toolchain (match, supply, deliver) via a minor fastlane bump; lockfile-only but failures would block CI archives and releases.

Overview
Updates Gemfile.lock only: fastlane 2.238.0 → 2.239.0, with refreshed transitive gems (notably google-apis-androidpublisher_v3 pinned to 0.99.0, google-cloud-env 2.3.1, http-cookie 1.1.6, and minor bumps to AWS/Google auth helpers).

No application source changes—CI still runs the same bundle exec fastlane lanes (archive, github_release, Maestro iOS). The new fastlane release adds supply/deliver/match/sigh fixes and raises the minimum Ruby to 3.1 upstream; verify macOS/Linux CI Ruby versions still satisfy that after merge.

Reviewed by Cursor Bugbot for commit 958ea3f. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [fastlane](https://github.com/fastlane/fastlane) from 2.238.0 to 2.239.0.
- [Release notes](https://github.com/fastlane/fastlane/releases)
- [Changelog](https://github.com/fastlane/fastlane/blob/master/CHANGELOG.latest.md)
- [Commits](fastlane/fastlane@fastlane/2.238.0...fastlane/2.239.0)

---
updated-dependencies:
- dependency-name: fastlane
  dependency-version: 2.239.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 8, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 8, 2026 06:43
@tonidero
tonidero enabled auto-merge (squash) September 8, 2026 06:48
@dependabot @github

dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #1090.

@dependabot dependabot Bot closed this Sep 18, 2026
auto-merge was automatically disabled September 18, 2026 06:42

Pull request was closed

@dependabot
dependabot Bot deleted the dependabot/bundler/fastlane-2.239.0 branch September 18, 2026 06:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant