Skip to content

Security: bump activesupport, rexml, yard#56

Draft
technicalpickles wants to merge 1 commit into
mainfrom
security/dep-sweep
Draft

Security: bump activesupport, rexml, yard#56
technicalpickles wants to merge 1 commit into
mainfrom
security/dep-sweep

Conversation

@technicalpickles

Copy link
Copy Markdown

Security Update

This PR addresses 11 critical security vulnerabilities across three transitive dependencies.

Gem Version GHSAs Severity
activesupport 7.0.4.3 → 8.1.3 ⚠️ GHSA-2j26-frm8-cmj9, GHSA-cg4j-q9v8-6v38, GHSA-89vf-4333-qx8v, GHSA-cr5q-6q9f-rq6q critical
rexml 3.2.5 → 3.4.4 GHSA-2rxp-v6pw-ch6m, GHSA-vmwr-mc7x-5vc3, GHSA-5866-49gr-22v4, GHSA-r55c-59qm-vjw6, GHSA-4xqq-m2hx-25v8, GHSA-vg3r-rm7w-2xgh critical
yard 0.9.36 → 0.9.44 GHSA-3jfp-46x4-xgfj critical

⚠️ Major Version Bump: activesupport moves from 7.0.4.3 to 8.1.3. This is a significant version change. Review the Rails 8 upgrade guide if needed.

Testing

All 20 existing tests pass with the updated dependencies.

- activesupport 7.0.4.3 -> 8.1.3 (major version bump)
- rexml 3.2.5 -> 3.4.4
- yard 0.9.36 -> 0.9.44

Addresses multiple security vulnerabilities across all three gems.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Triage

Development

Successfully merging this pull request may close these issues.

1 participant