Skip to content

Bump vulnerable deps to patch Dependabot alerts - #32

Merged
kylekeesling merged 1 commit into
masterfrom
bump-vulnerable-deps
Jul 14, 2026
Merged

Bump vulnerable deps to patch Dependabot alerts#32
kylekeesling merged 1 commit into
masterfrom
bump-vulnerable-deps

Conversation

@kylekeesling

@kylekeesling kylekeesling commented Jul 14, 2026

Copy link
Copy Markdown
Member

Bumps five gems in Gemfile.lock to resolve all 11 open Dependabot alerts (4 high, 4 medium, 3 low).

Gem Before After Alerts
faraday 2.14.0 2.14.3 #20 (high), #15 (low), #9 (medium)
concurrent-ruby 1.3.5 1.3.7 #18 (high), #19 (low), #17 (low)
activesupport 8.1.1 8.1.3 #13, #12, #11 (medium)
erb 5.1.3 6.0.4 #14 (high)
json 2.15.2 2.21.1 #10 (high)

Notable: faraday #20 (high) — stack-exhaustion DoS via deeply nested query params — is the only alert on a direct runtime dependency; the rest are transitive.

Conservative bundle update — only the affected gems moved. All 103 tests pass locally.

🤖 Generated with Claude Code


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.

Resolves 11 open Dependabot alerts (4 high, 4 medium, 3 low):
- faraday 2.14.0 -> 2.14.3 (#20 high, #15 low, #9 medium)
- concurrent-ruby 1.3.5 -> 1.3.7 (#18 high, #19 low, #17 low)
- activesupport 8.1.1 -> 8.1.3 (#13, #12, #11 medium)
- erb 5.1.3 -> 6.0.4 (#14 high)
- json 2.15.2 -> 2.21.1 (#10 high)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@kylekeesling
kylekeesling merged commit fb9afd8 into master Jul 14, 2026
5 checks passed
@kylekeesling
kylekeesling deleted the bump-vulnerable-deps branch July 14, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant