Skip to content

Bump pg from 1.6.3 to 1.7.0 - #675

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/pg-1.7.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/pg-1.7.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps pg from 1.6.3 to 1.7.0.

Changelog

Sourced from pg's changelog.

v1.7.0 [2026-10-02] Lars Kanis lars@greiz-reinsdorf.de

Added:

  • Add PG::Connection#embed_params and keyword :typename for its parameter casting. #726 This allows to generate SQL strings with embedded parameters for easier debugging.
  • Add PG::Connection#full_protocol_version which is new in PostgreSQL-18 #695
  • Add PG::Result#each_tuple #675
  • Add PG::TypeMap#query_param_encoders to retrieve encoders. #726
  • Deduplicate result field name strings for better performance. #750

Removed:

  • Remove compatibility to ruby < 3.1 and drops support of ruby-2.7 and ruby-3.0. #749
  • Remove GLV unlocking at all functions which process data modifiable in a second thread. #721 This avoids possible premature garbage collection of query parameters and possible VM crash due to concurrent data manipulation.
  • Remove :static_symbol result field names. #691
  • Remove enforced rpath addition when no rpath is configured in rbconfig. #699

Fixes:

  • Limit memory allocation on invalid input into PG::BinaryDecoder::Array. #743
  • Free COPY buffers when decoders raise to avoid possible memory leak in get_copy_data. #742
  • Prevent SQL injection in set_client_encoding. #741
  • Add GC_GUARD to temporary ruby objects for conninfo string to avoid it's GC'ed prematurely. #739
  • Remove option "quirks_mode" from JSON en/decoder to fix compat with json-3.0 gem. #737
  • Respect calendar type of Ruby and PostgreSQL. #725
  • Fix broken set_notice_(receiver|processor) callback after GC.compact. #734
  • Disable DNS resolution in ruby when a service file is used, so that the priority of parameters is equal to libpq. #635
  • Use RARRAY_LENINT to avoid possible overflow. #728
  • Fix possible integer overflow at PG::BinaryEncoder::CopyRow and PG::TextEncoder::CopyRow. #714, #715
  • Avoid possible integer overflow in query parameter encoding. #719
  • Ensure conninfo is a valid C string before closing the connection to avoid a double free of PGconn. #709
  • Raise on a too large input string to PG::TextEncoder::Bytea. #717
  • Check PG::BinaryEncoder::CopyRow array input size instead of producing an invalid output.
  • Remove accidentally copied "static" keyword from Copy and Record encoder. #711
  • Avoid possibility to replace typemap while being used in Copy and Record encoders and decoders. #707
  • Add GC_GUARD's for encoding converted strings sent to the server. #705
  • Fix incomplete transaction commit when thread is shutdown ungracefully. #704
  • Assign VALUE after registration per rb_gc_register_address() #703
  • Update dependencies for binary gems to PostgreSQL-18.6, OpenSSL-3.6.5, krb5-1.22.2 #752
Commits
  • fcf40c5 Add new gem signing certificate
  • d41e07a Merge pull request #753 from larskanis/rm-pgsql-10
  • 8e1ee8f Remove some conditions for PostgreSQL-10
  • 050c56d Fix typo in CHANGELOG and add version note
  • 2c4934e Bump VERSION to 1.7.0
  • f644ba2 Update release notes once more
  • b16542d Merge pull request #752 from larskanis/upd-binaries
  • 66b27c6 Update dependencies for binary gems to
  • 6a07394 Add CHANGELOG entry for pg-1.7.0
  • 5390356 Merge pull request #749 from larskanis/minruby-3.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pg](https://github.com/ged/ruby-pg) from 1.6.3 to 1.7.0.
- [Changelog](https://github.com/ged/ruby-pg/blob/master/CHANGELOG.md)
- [Commits](ged/ruby-pg@v1.6.3...v1.7.0)

---
updated-dependencies:
- dependency-name: pg
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies ruby Pull requests that update ruby code labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants