Skip to content

Bump json from 2.19.3 to 2.19.9 in /ruby/driver/riverqueue-activerecord - #1489

Merged
bgentry merged 1 commit into
masterfrom
dependabot/bundler/ruby/driver/riverqueue-activerecord/json-2.19.9
Oct 9, 2026
Merged

bgentry merged 1 commit into
masterfrom
dependabot/bundler/ruby/driver/riverqueue-activerecord/json-2.19.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps json from 2.19.3 to 2.19.9.

Release notes

Sourced from json's releases.

v2.19.9

  • Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with JSON.generate(object, io). [CVE-2026-54696].

Full Changelog: ruby/json@v2.19.8...v2.19.9

v2.19.8

What's Changed

  • Fix 1-byte buffer overread on EOS errors.
  • Handle invalid types passed as max_nesting option.

Full Changelog: ruby/json@v2.19.7...v2.19.8

v2.19.7

What's Changed

  • Fix some more edge cases with out of range floats.
  • Ensure the string provided to JSON.parse can't be mutated during parsing.
  • Add missing write barriers in State#dup.
  • Further validate generator depth config.

Full Changelog: ruby/json@v2.19.6...v2.19.7

v2.19.6

What's Changed

  • Cleanly handle overly large depth generator argument.
  • Add missing write barrier in ParserConfig.

Full Changelog: ruby/json@v2.19.5...v2.19.6

v2.19.5

What's Changed

  • Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.

Full Changelog: ruby/json@v2.19.4...v2.19.5

v2.19.4

What's Changed

  • Fix parsing of out of range floats (very large exponents that lead to either 0.0 or Inf).

Full Changelog: ruby/json@v2.19.2...v2.19.4

Changelog

Sourced from json's changelog.

2026-06-11 (2.19.9)

  • Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with JSON.generate(object, io). [CVE-2026-54696].

2026-06-03 (2.19.8)

  • Fix 1-byte buffer overread on EOS errors.
  • Handle invalid types passed as max_nesting option.

2026-05-28 (2.19.7)

  • Fix some more edge cases with out of range floats.
  • Ensure the string provided to JSON.parse can't be mutated during parsing.
  • Add missing write barriers in State#dup.
  • Further validate generator depth config.

2026-05-28 (2.19.6)

  • Cleanly handle overly large depth generator argument.
  • Add missing write barrier in ParserConfig.

2026-05-04 (2.19.5)

  • Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.

2026-04-19 (2.19.4)

  • Fix parsing of out of range floats (very large exponents that lead to either 0.0 or Inf).
Commits
  • 2cff267 Release 2.19.9
  • fd6a65b generator.c: don't start with a stack buffer in IO case
  • 5233dd9 Release 2.19.8
  • 3f44b26 Prevent buffer over-read when generating EOF error
  • be8d068 Handle invalid types passed as max_nesting option
  • 59501c0 Get rid of all_images gem
  • c7a7b2b Add a security note in README
  • ab6c8f2 Release 2.19.7
  • f033b9d Fix some more edge cases with out of range floats
  • 5ca8a67 parser.c: Ensure the user provided string can't be mutated
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [json](https://github.com/ruby/json) from 2.19.3 to 2.19.9.
- [Release notes](https://github.com/ruby/json/releases)
- [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md)
- [Commits](ruby/json@v2.19.3...v2.19.9)

---
updated-dependencies:
- dependency-name: json
  dependency-version: 2.19.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Oct 9, 2026

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Approved after dependency security and compatibility review.

Upgrade

  • json: 2.19.3 → 2.19.9, transitive in the Ruby Active Record adapter.
  • Reviewed head: fc101deff53f5501f5e7270d8df19ad527d81c30; base: a3ed70757b23ca63089b4476c8581af2f3144098.

Security review

  • Confirmed fix for CVE-2026-54696 / GHSA-x2f5-4prf-w687, a heap overflow in IO-streamed JSON generation. Inspected the actual buffer allocation/capacity fix and the complete published old-to-new native/runtime/build diff.
  • Downloaded both MRI source gems from RubyGems; registry SHA256 and internal archive checksums match. All 39 payload files in each artifact match the corresponding upstream source tag byte-for-byte. New gem SHA256: 9b9025b7cdddafa38d316eca0b2358488e42d417045c1b90d216a9fefe46b79a; the locally installed cache matches this reviewed identity.
  • Only the JSON version changes; no dependency graph, source, manifest constraints, build hooks, generated code, or same-version integrity rewrites. Existing C/mkmf/SIMD compilation remains expected. No new secret access, network/process hooks, or opaque payloads in the selected MRI artifact. Current exact-version advisory query reports no remaining advisories for 2.19.9.
  • Parallel per-PR static review is consolidated here; the coordinator performs validation and all GitHub writes.

Compatibility verification

  • Frozen bundle install --jobs=4 for all four Ruby bundles — passed. Local Ruby 3.3.12/macOS arm64 uses an isolated bundle; only temporary lockfile platform labels change from arm64-darwin-25 to arm64-darwin-27. All dependency entries remain exact and the PR itself is unchanged.
  • JSON IO streaming-boundary roundtrips (16,378–16,389 bytes), malformed trailing escape, invalid max_nesting, and excessive depth checks against loaded JSON 2.19.9 — passed.
  • make test/ruby, with RIVER_REQUIRE_DATABASES=1, both Postgres 18.6 and SQLite enabled against an isolated database — passed: core 986, Active Record 664, Sequel 641, Rails 66 examples; zero failures. One expected Ruby-4-only Ractor example is pending locally and covered by CI.
  • make lint/ruby typecheck/ruby verify/ruby-migrations build/ruby — passed, including all four gem builds.
  • make test, make lint, make tidy, make verify/migrations verify/rust-migrations verify/sqlc check/modzip, and CHECK=true make update-mod-go — passed. Go validation makes no tracked changes.
  • All current GitHub checks pass. The initial Postgres-14 Go job failed because a database IO timeout added a log line to the graceful-shutdown example's expected output; inspected the log and reran that job successfully on this same head. CI covers Ruby 3.2–4.0, Postgres 14–18, SQLite, Rails, Go race jobs, and Linux/Windows CLI. Bot CodeQL is neutral; no CodeQL analysis result is claimed.

Residual risk

  • Ordinary native-extension memory-safety risk and unsigned gem/source tags. Checksums and exact source equality establish content identity without cryptographic publisher attestation. JRuby Java artifacts are outside this MRI lockfile/CI scope. No blocking findings identified.

@bgentry
bgentry merged commit 2e37dd3 into master Oct 9, 2026
39 of 40 checks passed
@bgentry
bgentry deleted the dependabot/bundler/ruby/driver/riverqueue-activerecord/json-2.19.9 branch October 9, 2026 23:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant