Skip to content

Security: bump activesupport, addressable, json, mcp, yard#93

Draft
technicalpickles wants to merge 1 commit into
mainfrom
security/dep-sweep
Draft

Security: bump activesupport, addressable, json, mcp, yard#93
technicalpickles wants to merge 1 commit into
mainfrom
security/dep-sweep

Conversation

@technicalpickles

@technicalpickles technicalpickles commented Jun 18, 2026

Copy link
Copy Markdown

Summary

Security bumps for five dependencies with active CVEs/GHSA advisories.

Gem Old → New GHSA Severity
activesupport 8.1.2 → 8.1.3 GHSA-2j26-frm8-cmj9 High
activesupport 8.1.2 → 8.1.3 GHSA-89vf-4333-qx8v High
activesupport 8.1.2 → 8.1.3 GHSA-cg4j-q9v8-6v38 Medium
addressable 2.8.9 → 2.9.0 GHSA-h27x-rffw-24p4 High
json 2.18.1 → 2.19.9 GHSA-3m6g-2423-7cp3 Medium
mcp 0.8.0 → 0.9.2 GHSA-qvqr-5cv7-wh35 High
yard 0.9.38 → 0.9.44 GHSA-3jfp-46x4-xgfj Medium

All tests pass (rspec: 81 examples, 0 failures, 100% line coverage).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Triage

Development

Successfully merging this pull request may close these issues.

1 participant