Skip to content

Release Candidate: 9.1.1 - #6177

Merged
jamis merged 3 commits into
mongodb:masterfrom
jamis:rc-9.1.1
Sep 17, 2026
Merged

jamis merged 3 commits into
mongodb:masterfrom
jamis:rc-9.1.1

Conversation

@jamis

@jamis jamis commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

The MongoDB Ruby team is pleased to announce version 9.1.1 of the mongoid gem - a Ruby ODM for MongoDB. This is a new patch release in the 9.1.x series of Mongoid.

Install this release using RubyGems via the command line as follows:

gem install -v 9.1.1 mongoid

Or simply add it to your Gemfile:

gem 'mongoid', '9.1.1'

Have any feedback? Click on through to MongoDB's Jira and open a new ticket to let us know what's on your mind.

Bug Fixes

Bound regular-expression execution time in in-memory queries (MONGOID-5981)

Queries evaluated in memory, such as those against embedded associations, run in the calling thread and can spend an unbounded amount of CPU matching regular expressions. A single in-memory query is now limited by Mongoid.in_memory_regexp_time_limit (default 5.0 seconds); exceeding the limit raises Mongoid::Errors::InMemoryRegexpTimeout.

Fix encryption schema generation for automatic encryption (MONGOID-5984) (MONGOID-5989)

Automatic encryption schema generation no longer loops on models that embed themselves, and it now handles polymorphic embeds_one relations and embedded schemas that carry their own encryptMetadata correctly. A model whose collection has no entry in the generated schema is no longer written without encryption: such a write raises Mongoid::Errors::NoEncryptionSchema instead of storing the field in plaintext.

Resolve nested attribute ids within the caller's association (MONGOID-5992)

An id given in nested attributes is now resolved within the association the attributes are being applied to, rather than falling back to a collection-wide lookup that ignored default scopes. A document that is not part of that association raises Mongoid::Errors::DocumentNotFound, and a request to destroy a document that is not in the association is ignored. The Mongoid.allow_reparenting_via_nested_attributes option now defaults to false; set it to true to restore the previous reparenting behavior.

Reject the string form of where under the query operator guard (MONGOID-5993)

A String passed to #where is sent to MongoDB as a $where expression. This now raises Mongoid::Errors::InvalidQuery when Mongoid.allow_unsafe_query_operators is false (the default); the string form is allowed only when that option is enabled.

Reject JavaScript query operators at any depth (MONGOID-5994)

Mongoid.allow_unsafe_query_operators now defaults to false. When it is false, the $where, $function, and $accumulator operators are rejected anywhere in a query selector. The guard covers every criterion-building method (where, find_by, or, and, nor, not, any_of, none_of, and elem_match) and inspects nested expressions such as {'$expr' => {'$function' => ...}} in full.

Other Bug Fixes

  • In-memory queries, such as those executed against embedded associations, now read field names from the query as data rather than dispatching them as method calls on the document (MONGOID-5973)

@jamis
jamis requested a review from Jibola September 17, 2026 21:01
@jamis
jamis requested a review from a team as a code owner September 17, 2026 21:01
Copilot AI lite review requested due to automatic review settings September 17, 2026 21:01
@jamis jamis added the release-candidate The PR represents a potential candidate for a new release label Sep 17, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The PR description/release announcement text contains an inconsistent version number (9.1.11 vs 9.1.1) that should be corrected before release.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates the Mongoid patch release version metadata to prepare the 9.1.1 release candidate in the codebase.

Changes:

  • Bump Mongoid::VERSION from 9.1.0 to 9.1.1.
  • Update product.yml release version number to 9.1.1.
File summaries
File Description
product.yml Updates the product version number to 9.1.1.
lib/mongoid/version.rb Bumps Mongoid::VERSION constant to 9.1.1.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread lib/mongoid/version.rb
@jamis
jamis merged commit 381d954 into mongodb:master Sep 17, 2026
85 checks passed
@jamis
jamis deleted the rc-9.1.1 branch September 17, 2026 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release-candidate The PR represents a potential candidate for a new release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants