Skip to content

Commit 69dffe4

Browse files
chore(deps): bump json from 2.19.2 to 2.19.9 in /packages/react-native-sdk/dev/bare-rn (#676)
Bumps [json](https://github.com/ruby/json) from 2.19.2 to 2.19.9. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ruby/json/releases">json's releases</a>.</em></p> <blockquote> <h2>v2.19.9</h2> <ul> <li>Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with <code>JSON.generate(object, io)</code>. [CVE-2026-54696].</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/json/compare/v2.19.8...v2.19.9">https://github.com/ruby/json/compare/v2.19.8...v2.19.9</a></p> <h2>v2.19.8</h2> <h2>What's Changed</h2> <ul> <li>Fix 1-byte buffer overread on EOS errors.</li> <li>Handle invalid types passed as <code>max_nesting</code> option.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/json/compare/v2.19.7...v2.19.8">https://github.com/ruby/json/compare/v2.19.7...v2.19.8</a></p> <h2>v2.19.7</h2> <h2>What's Changed</h2> <ul> <li>Fix some more edge cases with out of range floats.</li> <li>Ensure the string provided to <code>JSON.parse</code> can't be mutated during parsing.</li> <li>Add missing write barriers in <code>State#dup</code>.</li> <li>Further validate generator <code>depth</code> config.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/json/compare/v2.19.6...v2.19.7">https://github.com/ruby/json/compare/v2.19.6...v2.19.7</a></p> <h2>v2.19.6</h2> <h2>What's Changed</h2> <ul> <li>Cleanly handle overly large <code>depth</code> generator argument.</li> <li>Add missing write barrier in <code>ParserConfig</code>.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/json/compare/v2.19.5...v2.19.6">https://github.com/ruby/json/compare/v2.19.5...v2.19.6</a></p> <h2>v2.19.5</h2> <h2>What's Changed</h2> <ul> <li>Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/json/compare/v2.19.4...v2.19.5">https://github.com/ruby/json/compare/v2.19.4...v2.19.5</a></p> <h2>v2.19.4</h2> <h2>What's Changed</h2> <ul> <li>Fix parsing of out of range floats (very large exponents that lead to either <code>0.0</code> or <code>Inf</code>).</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/json/compare/v2.19.2...v2.19.4">https://github.com/ruby/json/compare/v2.19.2...v2.19.4</a></p> <h2>v2.19.3</h2> <ul> <li>Fix handling of unescaped control characters preceeded by a backslash.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/ruby/json/compare/v2.19.2...v2.19.3">https://github.com/ruby/json/compare/v2.19.2...v2.19.3</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ruby/json/blob/master/CHANGES.md">json's changelog</a>.</em></p> <blockquote> <h3>2026-06-11 (2.19.9)</h3> <ul> <li>Fix buffer overflow that could lead to a crash when writing JSON directly into an IO with <code>JSON.generate(object, io)</code>. [CVE-2026-54696].</li> </ul> <h3>2026-06-03 (2.19.8)</h3> <ul> <li>Fix 1-byte buffer overread on EOS errors.</li> <li>Handle invalid types passed as <code>max_nesting</code> option.</li> </ul> <h3>2026-05-28 (2.19.7)</h3> <ul> <li>Fix some more edge cases with out of range floats.</li> <li>Ensure the string provided to <code>JSON.parse</code> can't be mutated during parsing.</li> <li>Add missing write barriers in <code>State#dup</code>.</li> <li>Further validate generator <code>depth</code> config.</li> </ul> <h3>2026-05-28 (2.19.6)</h3> <ul> <li>Cleanly handle overly large <code>depth</code> generator argument.</li> <li>Add missing write barrier in <code>ParserConfig</code>.</li> </ul> <h3>2026-05-04 (2.19.5)</h3> <ul> <li>Cap the parser to emit a maximum of 5 deprecation warnings per document. Emitting more is not helpful.</li> </ul> <h3>2026-04-19 (2.19.4)</h3> <ul> <li>Fix parsing of out of range floats (very large exponents that lead to either <code>0.0</code> or <code>Inf</code>).</li> </ul> <h3>2026-03-25 (2.19.3)</h3> <ul> <li>Fix handling of unescaped control characters preceeded by a backslash.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ruby/json/commit/2cff2678d5af54890a49da58345ac141b571f661"><code>2cff267</code></a> Release 2.19.9</li> <li><a href="https://github.com/ruby/json/commit/fd6a65bd08e5f3a429c03919ebfd8dd19158f095"><code>fd6a65b</code></a> generator.c: don't start with a stack buffer in IO case</li> <li><a href="https://github.com/ruby/json/commit/5233dd9b851a4924f793aec1a1658ed8b66a34c7"><code>5233dd9</code></a> Release 2.19.8</li> <li><a href="https://github.com/ruby/json/commit/3f44b26cf34f37e97065ff37f5eaecac69d5f28e"><code>3f44b26</code></a> Prevent buffer over-read when generating EOF error</li> <li><a href="https://github.com/ruby/json/commit/be8d068a8eb1124fdc2273e102dc986edf1140f7"><code>be8d068</code></a> Handle invalid types passed as <code>max_nesting</code> option</li> <li><a href="https://github.com/ruby/json/commit/59501c07de4257714d94a2d5bd44f08fad1a4a4c"><code>59501c0</code></a> Get rid of all_images gem</li> <li><a href="https://github.com/ruby/json/commit/c7a7b2be6f20e52439f4fdc5263e9b539fc6ad6c"><code>c7a7b2b</code></a> Add a security note in README</li> <li><a href="https://github.com/ruby/json/commit/ab6c8f2cdbc9cfa6079f5d0679afbc407a227c6d"><code>ab6c8f2</code></a> Release 2.19.7</li> <li><a href="https://github.com/ruby/json/commit/f033b9d3421c450108913d724810938e2d055e84"><code>f033b9d</code></a> Fix some more edge cases with out of range floats</li> <li><a href="https://github.com/ruby/json/commit/5ca8a67f52be73f68b7cd3b1f62809e3118c9d36"><code>5ca8a67</code></a> parser.c: Ensure the user provided string can't be mutated</li> <li>Additional commits viewable in <a href="https://github.com/ruby/json/compare/v2.19.2...v2.19.9">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=json&package-manager=bundler&previous-version=2.19.2&new-version=2.19.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/reflagcom/javascript/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent c29cc3d commit 69dffe4

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

‎packages/react-native-sdk/dev/bare-rn/Gemfile.lock‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -76,7 +76,7 @@ GEM
7676
mutex_m
7777
i18n (1.14.8)
7878
concurrent-ruby (~> 1.0)
79-
json (2.19.2)
79+
json (2.19.9)
8080
logger (1.7.0)
8181
minitest (5.27.0)
8282
molinillo (0.8.0)
@@ -145,7 +145,7 @@ CHECKSUMS
145145
gh_inspector (1.1.3) sha256=04cca7171b87164e053aa43147971d3b7f500fcb58177698886b48a9fc4a1939
146146
httpclient (2.9.0) sha256=4b645958e494b2f86c2f8a2f304c959baa273a310e77a2931ddb986d83e498c8
147147
i18n (1.14.8) sha256=285778639134865c5e0f6269e0b818256017e8cde89993fdfcbfb64d088824a5
148-
json (2.19.2) sha256=e7e1bd318b2c37c4ceee2444841c86539bc462e81f40d134cf97826cb14e83cf
148+
json (2.19.9) sha256=9b9025b7cdddafa38d316eca0b2358488e42d417045c1b90d216a9fefe46b79a
149149
logger (1.7.0) sha256=196edec7cc44b66cfb40f9755ce11b392f21f7967696af15d274dde7edff0203
150150
minitest (5.27.0) sha256=2d3b17f8a36fe7801c1adcffdbc38233b938eb0b4966e97a6739055a45fa77d5
151151
molinillo (0.8.0) sha256=efbff2716324e2a30bccd3eba1ff3a735f4d5d53ffddbc6a2f32c0ca9433045d

0 commit comments

Comments
 (0)