Skip to content

chore(deps): bump activesupport to patched 7.2+ line#56

Merged
alexstoick merged 1 commit into
masterfrom
security/bump-activesupport
Apr 15, 2026
Merged

chore(deps): bump activesupport to patched 7.2+ line#56
alexstoick merged 1 commit into
masterfrom
security/bump-activesupport

Conversation

@alexstoick
Copy link
Copy Markdown
Contributor

Summary

Note

Required resolving with Ruby >= 3.1 since activesupport 7.2+ has required_ruby_version >= 3.1.0. The gemspec has no Ruby version constraint so this is fine for consumers.

Closes dependabot alerts #10, #11, #12 (SafeBuffer XSS, ReDoS, DoS).
Minor Rails train bump (7.1 -> 7.2+) within gemspec constraints.
@alexstoick alexstoick merged commit fb98c8d into master Apr 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants