Build(deps): Bump rotp from 5.1.0 to 6.0.0 (PR #9530)

Bumps rotp from 5.1.0 to 6.0.0.

Changelog

Sourced from rotp's changelog.

6.0.0

  • Dropping support for Ruby <2.3 (Major version bump)
  • Fix issue when using --enable-frozen-string-literal Ruby option #95 (jeremyevans)
  • URI Encoding fix #94 (ksuh90)
  • Update gems (rake, addressable)
  • Update Travis tests to include Ruby 2.7
Commits
  • 5cf31c2 Update Readme regarding 6.0 dropping Ruby <2.3
  • 97475a1 Merge pull request #85 from amandameng/patch-1
  • 7af6858 Add in encoding fix for 6.0.0
  • 8ae63a8 Merge branch 'uri-encode-issuer' of https://github.com/ksuh90/rotp into ksuh9...
  • dd1e55b Update dependencies, remove Ruby <2.3 support
  • 5ec60df Fix issue when using --enable-frozen-string-literal Ruby option
  • a0ae135 URI encode the issuer parameter value
  • 5149825 Fix sample code
  • 4b22b7e Merge pull request #89 from olleolleolle/patch-1
  • 885187b gemspec: Drop EOL'd rubyforge_project property
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don’t alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a “Dependabot enabled” badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

GitHub

@featheredtoast the test failures seem to be because they’ve switched from + to %20 which should be the same. Do you think you could update the tests and this lib?

Hmmm, I just checked this out - it seems to be double-encoding in the library, so issuers spaces appear as %2520 ( url encodes to %20, which in turn url encodes to %2520) which seems… unexpected.

While it’s probably safe enough and won’t break anything, it would look weird for some authenticators, and honestly sounds like there’s still a bug in the lib version here… I’d hold off personally.

pinned the version, we can follow up depending on upstream

https://github.com/discourse/discourse/commit/85d4370f791a2e6e17a50cd9ab5de44cd1fcc0d2

OK, I won’t notify you again about this release, but will get in touch when a new version is available. If you’d rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I’ll resolve any conflicts on it.