-
Notifications
You must be signed in to change notification settings - Fork 23
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump json to fix CVE-2020-10663. #9
base: master
Are you sure you want to change the base?
Conversation
@incarnate, could you validate and merge this PR? |
I hope this is merged soon. It's a nightmare that every time I boot up my app: |
This also appears to cause problems in upgrading to Rails 7, and is stopping an upgrade in our application. Not sure if others have experienced this? This change really needs to be looked at, a new version with this does no harm whatsoever |
Looks like i've stumbled upon this one too in
Any progress on getting this in? as it's a complete deal breaker now in Rails 7 😢 |
Is there any progress on merging this PR? The latest version of the JSON gem is now 2.7.1 |
Considering there is no breaking change from json 2.1 to 2.3, I'm bumping the dependency to fix CVE-2020-10663