Skip to content

Bump the minor-and-patch group with 4 updates - #2735

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/minor-and-patch-3048c053d8
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/minor-and-patch-3048c053d8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 4 updates: dalli, sorbet-static, sorbet-static-and-runtime and spoom.

Updates dalli from 5.1.1 to 5.2.0

Release notes

Sourced from dalli's releases.

v5.2.0

Adds Dalli::CacheResult (#1156) and the opt-in defer_drain option (#1168), several get_multi/set/delete performance improvements from radixdev, and a fix for multi-server get_multi with empty values (#1170), which could silently return another key's value. Upgrading is recommended.

Features:

  • Add Dalli::CacheResult, returned by the new #get_with_metadata_result and #get_multi_with_metadata_result (#1156)
    • An opt-in, typed view over the Hash that #get_with_metadata and #get_multi_with_metadata already return; those methods are unchanged, and changing their return type is left for a future major version (#1151)
    • value, cas, hit_before, last_access and ttl_remaining readers (the last three are nil unless requested), plus miss?, hit?, stale?, won_recache? and lost_recache? predicates
    • Results are frozen, and a Hash that claims to be both a miss and stale raises ArgumentError
    • #get_multi_with_metadata_result omits misses and accepts req_options:, like #get_multi_with_metadata; it has no block form
  • Add the opt-in defer_drain client option (#1168)
    • With defer_drain: true, a quiet/multi block no longer waits at its end for the replies to its requests. The requests are still sent right away; the replies are read with one noop per server just before the next non-quiet request to that server
    • Adds Client#drain_deferred_responses, to drain at a boundary of the caller's choosing (the end of a web request or job)
    • Tradeoff: an error reply to a quiet request surfaces (and is discarded) at that later point, not at the end of the block
    • Off by default, so existing behavior is unchanged
    • Replies memcached sends for quiet requests wait on the connection until they're drained, so a client that only makes quiet requests should call drain_deferred_responses periodically; see "Deferred Draining" in the README
    • Thanks to Julian Richard Contreras and Matt Dick for this contribution

Performance:

  • Skip the empty read at the end of each pipelined read_available call (#1164)
    • A read shorter than the chunk size means the socket is drained, so the extra read_nonblock that only returned :wait_readable is gone; the IO.select loop still picks up anything that arrives later
    • Saves one syscall per server per multi-server get_multi; on 4 servers a 3-key get_multi goes from 16% to 5% slower than 2.7.11 in the #930 benchmark
    • TLS sockets also check SSLSocket#pending, since IO.select cannot see data OpenSSL has buffered
    • Thanks to Julian Richard Contreras for this contribution
  • Reduce Ruby overhead on plain set and delete (#1166)
    • A set with no CAS, routing tokens or quiet mode builds its ms request with one string interpolation (RequestFormatter.plain_meta_set), and a delete with no options uses plain_meta_delete; both produce the same bytes as before
    • HD c<cas>, HD and NF replies are parsed without splitting them into tokens
    • Allocations per set drop from 22 to 18, and per delete from 12 to 7
    • Thanks to Julian Richard Contreras for this contribution
  • Only drain servers that were sent quiet requests when a quiet/multi block ends (#1167)
    • Ending the block used to send a noop to every server in the ring and wait for each reply, one after another, so its cost grew with ring size even when the block touched one server (or none)
    • Each connection now records when a quiet request is written, and the block's drain skips the others; servers that were never connected are no longer connected just to be drained
    • With ~300us of network round trip, multi { set } on a 16-server ring goes from 4.9ms to 0.32ms; an empty block no longer touches the network
    • Thanks to Julian Richard Contreras for this contribution
  • Reduce Ruby overhead in get_multi reply parsing and key routing (#1169)
    • VA reply headers are read in place instead of being split into tokens, on both the multi-server (pipelined) and single-server paths; results are unchanged, and unusual headers still take the token path
    • A key's server is found through a bucket table over the ring's continuum instead of a binary search, and the key's own server is tried before the failover loop; the server chosen for every key is unchanged
    • Allocations for a 100-key get_multi on 4 servers drop from 1,500 to 1,104; over loopback it goes from 301us to 243us
    • Thanks to Julian Richard Contreras for this contribution

Bug fixes:

  • Fix multi-server get_multi stopping at an empty value (#1170)
    • The pipelined reply parser took a hit on a zero-length value (VA 0) for the terminating MN, so that server's remaining keys were silently missing from the result
    • Its value terminator and any replies not yet parsed stayed on the connection and were read as the replies to later commands on it. Those commands could fail with Dalli::DalliError: Response error, or a single-key get could silently return another key's value
    • An empty value is now returned as '', like a single-key get and single-server get_multi
    • Affects the meta protocol since 3.2.0 (the default since 5.0.0)
    • Thanks to Julian Richard Contreras for this contribution

... (truncated)

Changelog

Sourced from dalli's changelog.

5.2.0

Features:

  • Add Dalli::CacheResult, returned by the new #get_with_metadata_result and #get_multi_with_metadata_result (#1156)
    • An opt-in, typed view over the Hash that #get_with_metadata and #get_multi_with_metadata already return; those methods are unchanged, and changing their return type is left for a future major version (#1151)
    • value, cas, hit_before, last_access and ttl_remaining readers (the last three are nil unless requested), plus miss?, hit?, stale?, won_recache? and lost_recache? predicates
    • Results are frozen, and a Hash that claims to be both a miss and stale raises ArgumentError
    • #get_multi_with_metadata_result omits misses and accepts req_options:, like #get_multi_with_metadata; it has no block form
  • Add the opt-in defer_drain client option (#1168)
    • With defer_drain: true, a quiet/multi block no longer waits at its end for the replies to its requests. The requests are still sent right away; the replies are read with one noop per server just before the next non-quiet request to that server
    • Adds Client#drain_deferred_responses, to drain at a boundary of the caller's choosing (the end of a web request or job)
    • Tradeoff: an error reply to a quiet request surfaces (and is discarded) at that later point, not at the end of the block
    • Off by default, so existing behavior is unchanged
    • Replies memcached sends for quiet requests wait on the connection until they're drained, so a client that only makes quiet requests should call drain_deferred_responses periodically; see "Deferred Draining" in the README
    • Thanks to Julian Richard Contreras and Matt Dick for this contribution

Performance:

  • Skip the empty read at the end of each pipelined read_available call (#1164)
    • A read shorter than the chunk size means the socket is drained, so the extra read_nonblock that only returned :wait_readable is gone; the IO.select loop still picks up anything that arrives later
    • Saves one syscall per server per multi-server get_multi; on 4 servers a 3-key get_multi goes from 16% to 5% slower than 2.7.11 in the #930 benchmark
    • TLS sockets also check SSLSocket#pending, since IO.select cannot see data OpenSSL has buffered
    • Thanks to Julian Richard Contreras for this contribution
  • Reduce Ruby overhead on plain set and delete (#1166)
    • A set with no CAS, routing tokens or quiet mode builds its ms request with one string interpolation (RequestFormatter.plain_meta_set), and a delete with no options uses plain_meta_delete; both produce the same bytes as before
    • HD c<cas>, HD and NF replies are parsed without splitting them into tokens
    • Allocations per set drop from 22 to 18, and per delete from 12 to 7
    • Thanks to Julian Richard Contreras for this contribution
  • Only drain servers that were sent quiet requests when a quiet/multi block ends (#1167)
    • Ending the block used to send a noop to every server in the ring and wait for each reply, one after another, so its cost grew with ring size even when the block touched one server (or none)
    • Each connection now records when a quiet request is written, and the block's drain skips the others; servers that were never connected are no longer connected just to be drained
    • With ~300us of network round trip, multi { set } on a 16-server ring goes from 4.9ms to 0.32ms; an empty block no longer touches the network
    • Thanks to Julian Richard Contreras for this contribution
  • Reduce Ruby overhead in get_multi reply parsing and key routing (#1169)
    • VA reply headers are read in place instead of being split into tokens, on both the multi-server (pipelined) and single-server paths; results are unchanged, and unusual headers still take the token path
    • A key's server is found through a bucket table over the ring's continuum instead of a binary search, and the key's own server is tried before the failover loop; the server chosen for every key is unchanged
    • Allocations for a 100-key get_multi on 4 servers drop from 1,500 to 1,104; over loopback it goes from 301us to 243us
    • Thanks to Julian Richard Contreras for this contribution

Bug fixes:

  • Fix multi-server get_multi stopping at an empty value (#1170)
    • The pipelined reply parser took a hit on a zero-length value (VA 0) for the terminating MN, so that server's remaining keys were silently missing from the result
    • Its value terminator and any replies not yet parsed stayed on the connection and were read as the replies to later commands on it. Those commands could fail with Dalli::DalliError: Response error, or a single-key get could silently return another key's value
    • An empty value is now returned as '', like a single-key get and single-server get_multi
    • Affects the meta protocol since 3.2.0 (the default since 5.0.0)
    • Thanks to Julian Richard Contreras for this contribution
Commits
  • dc238e3 Merge pull request #1177 from petergoldstein/release/5.2.0
  • 55c838f Merge remote-tracking branch 'origin/main' into release/5.2.0
  • 57e6010 Merge pull request #1169 from radixdev/perf/get-multi-100
  • f3dfb2d Add PR number to changelog entry
  • 66f5a8d Speed up get_multi reply parsing and key routing
  • ae6a1e7 Prepare 5.2.0 release
  • c6b32b5 Merge pull request #1170 from radixdev/fix/empty-value-get-multi
  • e391403 Merge branch 'main' into fix/empty-value-get-multi
  • 79e542b Merge pull request #1172 from petergoldstein/ci/apt-update-before-install
  • 1bc2226 Refresh apt's package index before installing libevent in CI
  • Additional commits viewable in compare view

Updates sorbet-static from 0.6.13508 to 0.6.13524

Release notes

Sourced from sorbet-static's releases.

sorbet 0.6.13523.20261001173723-03e5ef830

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13523', :group => :development
gem 'sorbet-runtime', '0.6.13523'

sorbet 0.6.13522.20261001164920-269b5659a

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13522', :group => :development
gem 'sorbet-runtime', '0.6.13522'

sorbet 0.6.13521.20261001150158-e241b34d7

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13521', :group => :development
gem 'sorbet-runtime', '0.6.13521'

sorbet 0.6.13520.20261001144515-a386eb0ae

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13520', :group => :development
gem 'sorbet-runtime', '0.6.13520'

sorbet 0.6.13519.20261001161523-1a44eeb40

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13519', :group => :development
gem 'sorbet-runtime', '0.6.13519'

sorbet 0.6.13518.20261001110206-4653b77f8

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13518', :group => :development
gem 'sorbet-runtime', '0.6.13518'

sorbet 0.6.13517.20260930182708-477043d55

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13517', :group => :development
gem 'sorbet-runtime', '0.6.13517'

sorbet 0.6.13516.20260930123900-85ae358ac

... (truncated)

Commits

Updates sorbet-static-and-runtime from 0.6.13508 to 0.6.13524

Release notes

Sourced from sorbet-static-and-runtime's releases.

sorbet 0.6.13523.20261001173723-03e5ef830

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13523', :group => :development
gem 'sorbet-runtime', '0.6.13523'

sorbet 0.6.13522.20261001164920-269b5659a

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13522', :group => :development
gem 'sorbet-runtime', '0.6.13522'

sorbet 0.6.13521.20261001150158-e241b34d7

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13521', :group => :development
gem 'sorbet-runtime', '0.6.13521'

sorbet 0.6.13520.20261001144515-a386eb0ae

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13520', :group => :development
gem 'sorbet-runtime', '0.6.13520'

sorbet 0.6.13519.20261001161523-1a44eeb40

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13519', :group => :development
gem 'sorbet-runtime', '0.6.13519'

sorbet 0.6.13518.20261001110206-4653b77f8

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13518', :group => :development
gem 'sorbet-runtime', '0.6.13518'

sorbet 0.6.13517.20260930182708-477043d55

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13517', :group => :development
gem 'sorbet-runtime', '0.6.13517'

sorbet 0.6.13516.20260930123900-85ae358ac

... (truncated)

Commits

Updates spoom from 1.8.9 to 1.8.10

Release notes

Sourced from spoom's releases.

v1.8.10

What's Changed

🛠 Other Changes

Full Changelog: Shopify/spoom@v1.8.9...v1.8.10

Commits
  • a621b82 Bump version to v1.8.10
  • 2e13a79 Merge pull request #1026 from Shopify/at/count-struct-variants
  • 1c022e9 Merge pull request #1027 from Shopify/dependabot/github_actions/ruby/setup-ru...
  • 3dc49da Bump ruby/setup-ruby from 1.324.0 to 1.327.0
  • 954151e Collect metrics for inexact and immutable structs
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 4 updates: [dalli](https://github.com/petergoldstein/dalli), [sorbet-static](https://github.com/sorbet/sorbet), [sorbet-static-and-runtime](https://github.com/sorbet/sorbet) and [spoom](https://github.com/Shopify/spoom).


Updates `dalli` from 5.1.1 to 5.2.0
- [Release notes](https://github.com/petergoldstein/dalli/releases)
- [Changelog](https://github.com/petergoldstein/dalli/blob/main/CHANGELOG.md)
- [Commits](petergoldstein/dalli@v5.1.1...v5.2.0)

Updates `sorbet-static` from 0.6.13508 to 0.6.13524
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

Updates `sorbet-static-and-runtime` from 0.6.13508 to 0.6.13524
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)

Updates `spoom` from 1.8.9 to 1.8.10
- [Release notes](https://github.com/Shopify/spoom/releases)
- [Commits](Shopify/spoom@v1.8.9...v1.8.10)

---
updated-dependencies:
- dependency-name: dalli
  dependency-version: 5.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: sorbet-static
  dependency-version: 0.6.13524
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: sorbet-static-and-runtime
  dependency-version: 0.6.13524
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: spoom
  dependency-version: 1.8.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 5, 2026 21:44
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants