Repository navigation
Bump json from 2.19.3 to 2.19.9 in /ruby/driver/riverqueue-activerecord - #1489
Merged
bgentry merged 1 commit intoOct 9, 2026
Conversation
Bumps [json](https://github.com/ruby/json) from 2.19.3 to 2.19.9. - [Release notes](https://github.com/ruby/json/releases) - [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md) - [Commits](ruby/json@v2.19.3...v2.19.9) --- updated-dependencies: - dependency-name: json dependency-version: 2.19.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
bgentry
approved these changes
Oct 9, 2026
bgentry
left a comment
Contributor
There was a problem hiding this comment.
🤖 Codex review: Approved after dependency security and compatibility review.
Upgrade
json:2.19.3→2.19.9, transitive in the Ruby Active Record adapter.- Reviewed head:
fc101deff53f5501f5e7270d8df19ad527d81c30; base:a3ed70757b23ca63089b4476c8581af2f3144098.
Security review
- Confirmed fix for CVE-2026-54696 / GHSA-x2f5-4prf-w687, a heap overflow in IO-streamed JSON generation. Inspected the actual buffer allocation/capacity fix and the complete published old-to-new native/runtime/build diff.
- Downloaded both MRI source gems from RubyGems; registry SHA256 and internal archive checksums match. All 39 payload files in each artifact match the corresponding upstream source tag byte-for-byte. New gem SHA256:
9b9025b7cdddafa38d316eca0b2358488e42d417045c1b90d216a9fefe46b79a; the locally installed cache matches this reviewed identity. - Only the JSON version changes; no dependency graph, source, manifest constraints, build hooks, generated code, or same-version integrity rewrites. Existing C/mkmf/SIMD compilation remains expected. No new secret access, network/process hooks, or opaque payloads in the selected MRI artifact. Current exact-version advisory query reports no remaining advisories for 2.19.9.
- Parallel per-PR static review is consolidated here; the coordinator performs validation and all GitHub writes.
Compatibility verification
- Frozen
bundle install --jobs=4for all four Ruby bundles — passed. Local Ruby 3.3.12/macOS arm64 uses an isolated bundle; only temporary lockfile platform labels change fromarm64-darwin-25toarm64-darwin-27. All dependency entries remain exact and the PR itself is unchanged. - JSON IO streaming-boundary roundtrips (16,378–16,389 bytes), malformed trailing escape, invalid max_nesting, and excessive depth checks against loaded JSON 2.19.9 — passed.
make test/ruby, withRIVER_REQUIRE_DATABASES=1, both Postgres 18.6 and SQLite enabled against an isolated database — passed: core 986, Active Record 664, Sequel 641, Rails 66 examples; zero failures. One expected Ruby-4-only Ractor example is pending locally and covered by CI.make lint/ruby typecheck/ruby verify/ruby-migrations build/ruby— passed, including all four gem builds.make test,make lint,make tidy,make verify/migrations verify/rust-migrations verify/sqlc check/modzip, andCHECK=true make update-mod-go— passed. Go validation makes no tracked changes.- All current GitHub checks pass. The initial Postgres-14 Go job failed because a database IO timeout added a log line to the graceful-shutdown example's expected output; inspected the log and reran that job successfully on this same head. CI covers Ruby 3.2–4.0, Postgres 14–18, SQLite, Rails, Go race jobs, and Linux/Windows CLI. Bot CodeQL is neutral; no CodeQL analysis result is claimed.
Residual risk
- Ordinary native-extension memory-safety risk and unsigned gem/source tags. Checksums and exact source equality establish content identity without cryptographic publisher attestation. JRuby Java artifacts are outside this MRI lockfile/CI scope. No blocking findings identified.
bgentry
deleted the
dependabot/bundler/ruby/driver/riverqueue-activerecord/json-2.19.9
branch
October 9, 2026 23:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps json from 2.19.3 to 2.19.9.
Release notes
Sourced from json's releases.
Changelog
Sourced from json's changelog.
Commits
2cff267Release 2.19.9fd6a65bgenerator.c: don't start with a stack buffer in IO case5233dd9Release 2.19.83f44b26Prevent buffer over-read when generating EOF errorbe8d068Handle invalid types passed asmax_nestingoption59501c0Get rid of all_images gemc7a7b2bAdd a security note in READMEab6c8f2Release 2.19.7f033b9dFix some more edge cases with out of range floats5ca8a67parser.c: Ensure the user provided string can't be mutatedDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.