Skip to content

Bump json from 2.19.3 to 2.19.9 in /ruby - #1478

Merged
bgentry merged 1 commit into
masterfrom
dependabot/bundler/ruby/json-2.19.9
Oct 8, 2026
Merged

bgentry merged 1 commit into
masterfrom
dependabot/bundler/ruby/json-2.19.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps json from 2.19.3 to 2.19.9.

Release notes

Sourced from json's releases.

v2.19.9

  • Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with JSON.generate(object, io). [CVE-2026-54696].

Full Changelog: ruby/json@v2.19.8...v2.19.9

v2.19.8

What's Changed

  • Fix 1-byte buffer overread on EOS errors.
  • Handle invalid types passed as max_nesting option.

Full Changelog: ruby/json@v2.19.7...v2.19.8

v2.19.7

What's Changed

  • Fix some more edge cases with out of range floats.
  • Ensure the string provided to JSON.parse can't be mutated during parsing.
  • Add missing write barriers in State#dup.
  • Further validate generator depth config.

Full Changelog: ruby/json@v2.19.6...v2.19.7

v2.19.6

What's Changed

  • Cleanly handle overly large depth generator argument.
  • Add missing write barrier in ParserConfig.

Full Changelog: ruby/json@v2.19.5...v2.19.6

v2.19.5

What's Changed

  • Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.

Full Changelog: ruby/json@v2.19.4...v2.19.5

v2.19.4

What's Changed

  • Fix parsing of out of range floats (very large exponents that lead to either 0.0 or Inf).

Full Changelog: ruby/json@v2.19.2...v2.19.4

Changelog

Sourced from json's changelog.

2026-06-11 (2.19.9)

  • Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with JSON.generate(object, io). [CVE-2026-54696].

2026-06-03 (2.19.8)

  • Fix 1-byte buffer overread on EOS errors.
  • Handle invalid types passed as max_nesting option.

2026-05-28 (2.19.7)

  • Fix some more edge cases with out of range floats.
  • Ensure the string provided to JSON.parse can't be mutated during parsing.
  • Add missing write barriers in State#dup.
  • Further validate generator depth config.

2026-05-28 (2.19.6)

  • Cleanly handle overly large depth generator argument.
  • Add missing write barrier in ParserConfig.

2026-05-04 (2.19.5)

  • Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.

2026-04-19 (2.19.4)

  • Fix parsing of out of range floats (very large exponents that lead to either 0.0 or Inf).
Commits
  • 2cff267 Release 2.19.9
  • fd6a65b generator.c: don't start with a stack buffer in IO case
  • 5233dd9 Release 2.19.8
  • 3f44b26 Prevent buffer over-read when generating EOF error
  • be8d068 Handle invalid types passed as max_nesting option
  • 59501c0 Get rid of all_images gem
  • c7a7b2b Add a security note in README
  • ab6c8f2 Release 2.19.7
  • f033b9d Fix some more edge cases with out of range floats
  • 5ca8a67 parser.c: Ensure the user provided string can't be mutated
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Oct 8, 2026
@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/bundler/ruby/json-2.19.9 branch from d07782f to 6398a43 Compare October 8, 2026 15:16
@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [json](https://github.com/ruby/json) from 2.19.3 to 2.19.9.
- [Release notes](https://github.com/ruby/json/releases)
- [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md)
- [Commits](ruby/json@v2.19.3...v2.19.9)

---
updated-dependencies:
- dependency-name: json
  dependency-version: 2.19.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/ruby/json-2.19.9 branch from 6398a43 to d3ff5fe Compare October 8, 2026 15:26

@bgentry bgentry left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Approved after dependency security and compatibility review.

Upgrade

  • json: 2.19.3 → 2.19.9 in the root Ruby bundle.
  • Reviewed head: d3ff5feaf1a226355250522d8b2afcf558049757 Validated against current master a9c936990a689d00c8899ecf0aaba7a4ef7ab28a, including the reviewed SQLite3 update in #1479 and concurrent documentation merge #1482. The prospective merge tree is d99ca2033f4ed5532b206d822f8b6c5d746f77dc (temporary local merge commit 4b9d5edad3fccc414ed34035e7a4417eee1d1c39).

Security review

  • Compared both official Ruby-platform gems and all 39 shipped files per version against exact upstream sources 779d4415a077e24cfaa00208f39dba825f2e0ae8 → 2cff2678d5af54890a49da58345ac141b571f661. Artifacts match upstream byte-for-byte, RubyGems platform-specific SHA256 metadata, and internal checksums.
  • json-2.19.3.gem: SHA256 289b0bb53052a1fa8c34ab33cc750b659ba14a5c45f3fcf4b18762dc67c78646; json-2.19.9.gem: SHA256 9b9025b7cdddafa38d316eca0b2358488e42d417045c1b90d216a9fefe46b79a. The installed target gem cache matches this reviewed hash.
  • Inspected the complete published artifact diff (11 changed files), including native IO buffer allocation/growth, parser bounds and exponent handling, GC/write barriers, and compiler feature checks. No new shipped files, binaries, runtime dependencies, hooks, network endpoints, credential access, process spawning, or registry/repository changes. Vendored conversion code is unchanged; publisher and canonical source remain the expected byroot / ruby/json.
  • Confirmed CVE-2026-54696 / GHSA-x2f5-4prf-w687: >=2.9.0, <2.19.9 affected; 2.19.9 first patched. The native IO streaming buffer fix is present. Checked all six GitHub-reviewed JSON gem advisories; none lists 2.19.9 as affected by an unresolved advisory.
  • Reused the exact artifact/checksum and old-to-new evidence across both rebases. Current-head security delta is only the independently reviewed SQLite3 update in the Sequel bundle; this PR itself remains one root-lock version change, with no transitive churn, registry change, or same-version checksum rewrite.

Compatibility verification

  • Current combined tree validated locally with Ruby 3.3.1, Bundler 4.0.9, Postgres 18.6, and native arm64 SQLite. All four frozen bundle installations passed after adding only the local Darwin platform to temporary lockfiles. Automated comparison confirms all other lock content remains identical; original lockfiles were restored.
  • RIVER_REQUIRE_DATABASES=1 TEST_DATABASE_URL=postgres://localhost/river_test make test/ruby — passed across core, Active Record, Sequel, Rails, Postgres, SQLite, and Go-generated conformance fixtures: 2,357 examples, zero failures; one expected Ruby-4-only Ractor example pending on Ruby 3.3. Core and both driver suites report 100% line/branch coverage.
  • make lint/ruby and make -C ruby type-check verify build — passed, including all four gem archives; no tracked source changes.
  • Ephemeral JSON IO regression around the 16 KB buffer boundary, escaped quotes/backslashes/control characters, and UTF-8 — all 35 stream/non-stream equivalence and round-trip cases passed with JSON::VERSION == "2.19.9".
  • CI passed on the reviewed PR head before #1482 merged concurrently, including Ruby 3.2–4.0, Postgres 14–18, SQLite, Rails 7.2/8.0/8.1, quality checks, and packaging. I then reran every local check above on the prospective merge with current master. Its only diff from master is the one JSON lockfile version line. The base update changes relevant Ruby wording and SQL comments plus their manifest checksums; there are no dependency identities or execution-context changes. CodeQL is neutral on this bot-authored PR.

Residual risk

  • Gems have empty signing certificate chains; integrity was independently checked against registry metadata and upstream source, without a separate signed provenance assertion. Native C memory safety is not formally proven. No blocking issue identified.

@bgentry
bgentry merged commit f1d9692 into master Oct 8, 2026
26 checks passed
@bgentry
bgentry deleted the dependabot/bundler/ruby/json-2.19.9 branch October 8, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant