Skip to content

chore(deps): bump json from 2.15.2.1 to 2.21.2 in /.github - #384

Merged
josegonzalez merged 1 commit into
mainfrom
62-security-dependabot
Aug 1, 2026
Merged

chore(deps): bump json from 2.15.2.1 to 2.21.2 in /.github#384
josegonzalez merged 1 commit into
mainfrom
62-security-dependabot

Conversation

@josegonzalez

Copy link
Copy Markdown
Member

Bumps the json gem in .github/Gemfile.lock from 2.15.2.1 to 2.21.2 to resolve Dependabot security alert #62 (GHSA-x2f5-4prf-w687 / CVE-2026-54696). The advisory describes a heap out-of-bounds write in the JSON generator's IO-streaming path (JSON.dump(obj, io) and JSON::State#generate(obj, io)) that can be triggered by an attacker-controlled string near 16 KB, resulting in a reliable denial of service. The affected range is >= 2.9.0, < 2.19.9, so the previously pinned 2.15.2.1 was vulnerable; 2.21.2 is the latest release and still satisfies package_cloud's ~> 2.9 requirement. The gem is a transitive dependency exercised only by the tagged-release workflow, and because it has no runtime dependencies of its own the update is limited to a single lockfile line.

@josegonzalez
josegonzalez merged commit 4757965 into main Aug 1, 2026
8 checks passed
@josegonzalez
josegonzalez deleted the 62-security-dependabot branch August 1, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant