Skip to content

chore: bump json from 2.15.2.1 to 2.21.2 - #403

Open
josegonzalez wants to merge 1 commit into
mainfrom
dependabot-90-ruby-json-json-generator-heap-buffer-overflow-when-streaming-to-an-io
Open

chore: bump json from 2.15.2.1 to 2.21.2#403
josegonzalez wants to merge 1 commit into
mainfrom
dependabot-90-ruby-json-json-generator-heap-buffer-overflow-when-streaming-to-an-io

Conversation

@josegonzalez

@josegonzalez josegonzalez commented Aug 2, 2026

Copy link
Copy Markdown
Member

Patches CVE-2026-54696 (GHSA-x2f5-4prf-w687), a low-severity heap buffer overflow in the json generator's IO-streaming path, resolving Dependabot alert #90.

json is a transitive dependency of package_cloud used only by the tagged-release workflow to build .deb packages, and was pinned in .github/Gemfile.lock at 2.15.2.1, inside the vulnerable range >= 2.9.0, < 2.19.9. The new version 2.21.2 is past the first patched release 2.19.9 and satisfies package_cloud's json (~> 2.9) constraint. Since json has no runtime dependencies, this is a single-line lockfile change equivalent to a conservative bundle lock --update json.

Patches CVE-2026-54696 (GHSA-x2f5-4prf-w687), a low-severity heap buffer overflow in the `json` generator's IO-streaming path, resolving Dependabot alert #90.
@josegonzalez
josegonzalez force-pushed the dependabot-90-ruby-json-json-generator-heap-buffer-overflow-when-streaming-to-an-io branch from 0f05b6b to 70b7a10 Compare August 2, 2026 07:08
@josegonzalez josegonzalez changed the title chore: bump json from 2.15.2.1 to 2.19.9 chore: bump json from 2.15.2.1 to 2.21.2 Aug 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant