Skip to content

Update the lockfile for the open advisories - #16

Merged
usiegj00 merged 1 commit into
mainfrom
security-lockfile-updates
Sep 10, 2026
Merged

usiegj00 merged 1 commit into
mainfrom
security-lockfile-updates

Conversation

@usiegj00

Copy link
Copy Markdown
Contributor

Clears all 20 Dependabot alerts:

gem from to severity
activesupport 7.2.2.2 8.1.3.1 3 medium
addressable 2.8.7 2.9.0 high
erb 4.0.4 6.0.7 high
faraday 2.13.4 2.14.3 high, medium, low
nokogiri 1.18.9 1.19.4 high, 3 medium, 7 low
uri 1.0.3 1.0.4 low

No re-release needed. Lockfile pins only — the gemspec asks for activesupport >= 7.0, faraday ~> 2.0, nokogiri ~> 1.14, so installs of radfish 0.3.0 already resolve patched versions.

Worth a second opinion on one point: activesupport and erb crossed major versions (7.x → 8.x, 4.x → 6.x). The suite is green on both, so CI now exercises activesupport 8 while the gemspec still permits 7. Say the word if you would rather hold activesupport at 7.2.3.1.

76 examples, 0 failures.

Clears all 20 Dependabot alerts: activesupport 7.2.2.2 -> 8.1.3.1
(3 medium), addressable 2.8.7 -> 2.9.0 (high), erb 4.0.4 -> 6.0.7
(high), faraday 2.13.4 -> 2.14.3 (high, medium, low), nokogiri
1.18.9 -> 1.19.4 (high, 3 medium, 7 low), uri 1.0.3 -> 1.0.4 (low).

Lockfile pins only, so this affects CI here rather than anyone
installing the gem: the gemspec asks for activesupport >= 7.0,
faraday ~> 2.0 and nokogiri ~> 1.14, all of which already resolve to
patched versions. No re-release needed.

Note that activesupport and erb crossed major versions. The suite is
green on both, and CI now exercises activesupport 8.x while the gemspec
still allows 7.x.
@usiegj00
usiegj00 merged commit 3e0b26e into main Sep 10, 2026
1 check passed
@usiegj00
usiegj00 deleted the security-lockfile-updates branch September 10, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant