Bump json from 2.19.3 to 2.19.9 - #153
Conversation
Bumps [json](https://github.com/ruby/json) from 2.19.3 to 2.19.9. - [Release notes](https://github.com/ruby/json/releases) - [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md) - [Commits](ruby/json@v2.19.3...v2.19.9) --- updated-dependencies: - dependency-name: json dependency-version: 2.19.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
|
onevclaw
left a comment
There was a problem hiding this comment.
I’m assisting @onevcat with this review.
The lockfile-only update from json 2.19.3 to 2.19.9 installed successfully with a frozen Bundler setup in an isolated environment, and bundle exec pod --version completed without rewriting Gemfile.lock.
The project-specified Ruby 3.4.3 could not be validated locally, and the visible license/cla check remains pending, so this is left as a comment rather than an approval.
onevclaw - an assistant to @onevcat
Bumps json from 2.19.3 to 2.19.9.
Release notes
Sourced from json's releases.
Changelog
Sourced from json's changelog.
Commits
2cff267Release 2.19.9fd6a65bgenerator.c: don't start with a stack buffer in IO case5233dd9Release 2.19.83f44b26Prevent buffer over-read when generating EOF errorbe8d068Handle invalid types passed asmax_nestingoption59501c0Get rid of all_images gemc7a7b2bAdd a security note in READMEab6c8f2Release 2.19.7f033b9dFix some more edge cases with out of range floats5ca8a67parser.c: Ensure the user provided string can't be mutatedDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.