Skip to content

Security: bump activesupport, addressable, json, mcp, yard#93

Merged
technicalpickles merged 2 commits into
mainfrom
security/dep-sweep
Jun 24, 2026
Merged

Security: bump activesupport, addressable, json, mcp, yard#93
technicalpickles merged 2 commits into
mainfrom
security/dep-sweep

Conversation

@technicalpickles

@technicalpickles technicalpickles commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Security bumps for five dependencies with active CVEs/GHSA advisories.

Gem Old → New GHSA Severity
activesupport 8.1.2 → 8.1.3 GHSA-2j26-frm8-cmj9 High
activesupport 8.1.2 → 8.1.3 GHSA-89vf-4333-qx8v High
activesupport 8.1.2 → 8.1.3 GHSA-cg4j-q9v8-6v38 Medium
addressable 2.8.9 → 2.9.0 GHSA-h27x-rffw-24p4 High
json 2.18.1 → 2.19.9 GHSA-3m6g-2423-7cp3 Medium
mcp 0.8.0 → 0.9.2 GHSA-qvqr-5cv7-wh35 High
yard 0.9.38 → 0.9.44 GHSA-3jfp-46x4-xgfj Medium

All tests pass (rspec: 81 examples, 0 failures, 100% line coverage).

The temp-pin technique promoted yard to a direct dependency in the
DEPENDENCIES section of Gemfile.lock, but yard is not in the Gemfile
or gemspec. This caused `bundle install --frozen` to fail in CI.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@technicalpickles technicalpickles marked this pull request as ready for review June 24, 2026 18:55
@technicalpickles technicalpickles requested a review from a team as a code owner June 24, 2026 18:55
@technicalpickles technicalpickles enabled auto-merge (squash) June 24, 2026 19:57
@technicalpickles technicalpickles merged commit 342eec5 into main Jun 24, 2026
8 checks passed
@technicalpickles technicalpickles deleted the security/dep-sweep branch June 24, 2026 19:58
@github-project-automation github-project-automation Bot moved this from Triage to Done in Modularity Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant