Skip to content

Bump json to a patched release for the DoS advisory - #49

Open
martijnversluis wants to merge 1 commit into
mainfrom
bump-json-for-cve
Open

Bump json to a patched release for the DoS advisory#49
martijnversluis wants to merge 1 commit into
mainfrom
bump-json-for-cve

Conversation

@martijnversluis

Copy link
Copy Markdown
Contributor

Sluit de openstaande Dependabot-advisory (GHSA) voor de json gem: versie 2.19.5 valt binnen het kwetsbare bereik (>= 2.9.0, < 2.19.9). Bumpt naar 2.21.2.

json is een transitieve dependency, dus alleen Gemfile.lock verandert. Er stond nog geen Dependabot-PR voor open. Specs groen (zaptec 70, easee 60).

@martijnversluis

Copy link
Copy Markdown
Contributor Author

@claude review deze security bump graag.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant