Pin rubocop to ~> 1.91.0 and fix Style/DirectiveScope offenses - #2086
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related to #2085
Proposed changes
rubocopto~> 1.91.0in the gemspec (was~> 1.82, which floats to any newer 1.x).rubocop:disable/rubocop:enablepairs into therubocop:disable-nextdirective introduced in rubocop 1.91. Comment-only change, applied byrubocop -A --only Style/DirectiveScope.Why are these changes being made?
CI on #2085 failed on
bundle exec rubocopwith 5Style/DirectiveScopeoffenses, none of them related to that PR. The cop is new in rubocop 1.91.0 (released 2026-09-10, rubocop/rubocop#15601). Because there is no committed lockfile,.rubocop.ymlhasNewCops: enable, and the gemspec only set a floor, every fresh CI run picks up the newest rubocop and enforces whatever it adds. Master was last green on 2026-08-20 with an older rubocop and would fail the same way today.Pinning to the patch series turns this into a normal dependabot bump PR, where new offenses show up and get fixed in the same change instead of breaking unrelated PRs.
disable-nextis only understood by rubocop >= 1.91, which is why the pin and the comment changes land together.Testing instructions
Trust the CI.
Licensing
By submitting code contributions to the WPScan development team via Github Pull Requests, or any other method, it is understood that the contributor grants Automattic Inc. the unlimited, non-exclusive right to reuse, modify, and relicense the code.