From 70b7a109c54e4e448316cc7a58c44f45cd899fd6 Mon Sep 17 00:00:00 2001 From: Jose Diaz-Gonzalez Date: Sun, 2 Aug 2026 03:05:12 -0400 Subject: [PATCH] chore: bump json from 2.15.2.1 to 2.21.2 Patches CVE-2026-54696 (GHSA-x2f5-4prf-w687), a low-severity heap buffer overflow in the `json` generator's IO-streaming path, resolving Dependabot alert #90. --- .github/Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/Gemfile.lock b/.github/Gemfile.lock index 6f90dd1..ca1841d 100644 --- a/.github/Gemfile.lock +++ b/.github/Gemfile.lock @@ -21,7 +21,7 @@ GEM http-cookie (1.1.0) domain_name (~> 0.5) insist (1.0.0) - json (2.15.2.1) + json (2.21.2) logger (1.7.0) mime-types (3.7.0) logger