Repository navigation
Bump json from 2.19.3 to 2.19.9 in /ruby - #1478
Merged
Merged
Conversation
Contributor
|
@dependabot rebase |
dependabot
Bot
force-pushed
the
dependabot/bundler/ruby/json-2.19.9
branch
from
October 8, 2026 15:16
d07782f to
6398a43
Compare
Contributor
|
@dependabot rebase |
Bumps [json](https://github.com/ruby/json) from 2.19.3 to 2.19.9. - [Release notes](https://github.com/ruby/json/releases) - [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md) - [Commits](ruby/json@v2.19.3...v2.19.9) --- updated-dependencies: - dependency-name: json dependency-version: 2.19.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/bundler/ruby/json-2.19.9
branch
from
October 8, 2026 15:26
6398a43 to
d3ff5fe
Compare
bgentry
approved these changes
Oct 8, 2026
Contributor
There was a problem hiding this comment.
🤖 Codex review: Approved after dependency security and compatibility review.
Upgrade
json:2.19.3→2.19.9in the root Ruby bundle.- Reviewed head:
d3ff5feaf1a226355250522d8b2afcf558049757Validated against current mastera9c936990a689d00c8899ecf0aaba7a4ef7ab28a, including the reviewed SQLite3 update in #1479 and concurrent documentation merge #1482. The prospective merge tree isd99ca2033f4ed5532b206d822f8b6c5d746f77dc(temporary local merge commit4b9d5edad3fccc414ed34035e7a4417eee1d1c39).
Security review
- Compared both official Ruby-platform gems and all 39 shipped files per version against exact upstream sources
779d4415a077e24cfaa00208f39dba825f2e0ae8→2cff2678d5af54890a49da58345ac141b571f661. Artifacts match upstream byte-for-byte, RubyGems platform-specific SHA256 metadata, and internal checksums. json-2.19.3.gem: SHA256289b0bb53052a1fa8c34ab33cc750b659ba14a5c45f3fcf4b18762dc67c78646;json-2.19.9.gem: SHA2569b9025b7cdddafa38d316eca0b2358488e42d417045c1b90d216a9fefe46b79a. The installed target gem cache matches this reviewed hash.- Inspected the complete published artifact diff (11 changed files), including native IO buffer allocation/growth, parser bounds and exponent handling, GC/write barriers, and compiler feature checks. No new shipped files, binaries, runtime dependencies, hooks, network endpoints, credential access, process spawning, or registry/repository changes. Vendored conversion code is unchanged; publisher and canonical source remain the expected
byroot/ ruby/json. - Confirmed CVE-2026-54696 / GHSA-x2f5-4prf-w687:
>=2.9.0, <2.19.9affected;2.19.9first patched. The native IO streaming buffer fix is present. Checked all six GitHub-reviewed JSON gem advisories; none lists2.19.9as affected by an unresolved advisory. - Reused the exact artifact/checksum and old-to-new evidence across both rebases. Current-head security delta is only the independently reviewed SQLite3 update in the Sequel bundle; this PR itself remains one root-lock version change, with no transitive churn, registry change, or same-version checksum rewrite.
Compatibility verification
- Current combined tree validated locally with Ruby
3.3.1, Bundler4.0.9, Postgres18.6, and native arm64 SQLite. All four frozen bundle installations passed after adding only the local Darwin platform to temporary lockfiles. Automated comparison confirms all other lock content remains identical; original lockfiles were restored. RIVER_REQUIRE_DATABASES=1 TEST_DATABASE_URL=postgres://localhost/river_test make test/ruby— passed across core, Active Record, Sequel, Rails, Postgres, SQLite, and Go-generated conformance fixtures: 2,357 examples, zero failures; one expected Ruby-4-only Ractor example pending on Ruby 3.3. Core and both driver suites report 100% line/branch coverage.make lint/rubyandmake -C ruby type-check verify build— passed, including all four gem archives; no tracked source changes.- Ephemeral JSON IO regression around the 16 KB buffer boundary, escaped quotes/backslashes/control characters, and UTF-8 — all 35 stream/non-stream equivalence and round-trip cases passed with
JSON::VERSION == "2.19.9". - CI passed on the reviewed PR head before #1482 merged concurrently, including Ruby 3.2–4.0, Postgres 14–18, SQLite, Rails 7.2/8.0/8.1, quality checks, and packaging. I then reran every local check above on the prospective merge with current master. Its only diff from master is the one JSON lockfile version line. The base update changes relevant Ruby wording and SQL comments plus their manifest checksums; there are no dependency identities or execution-context changes. CodeQL is neutral on this bot-authored PR.
Residual risk
- Gems have empty signing certificate chains; integrity was independently checked against registry metadata and upstream source, without a separate signed provenance assertion. Native C memory safety is not formally proven. No blocking issue identified.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps json from 2.19.3 to 2.19.9.
Release notes
Sourced from json's releases.
Changelog
Sourced from json's changelog.
Commits
2cff267Release 2.19.9fd6a65bgenerator.c: don't start with a stack buffer in IO case5233dd9Release 2.19.83f44b26Prevent buffer over-read when generating EOF errorbe8d068Handle invalid types passed asmax_nestingoption59501c0Get rid of all_images gemc7a7b2bAdd a security note in READMEab6c8f2Release 2.19.7f033b9dFix some more edge cases with out of range floats5ca8a67parser.c: Ensure the user provided string can't be mutated