Bump json to fix CVE-2020-10663.#9
Conversation
|
@incarnate, could you validate and merge this PR? |
|
I hope this is merged soon. It's a nightmare that every time I boot up my app: |
|
This also appears to cause problems in upgrading to Rails 7, and is stopping an upgrade in our application. Not sure if others have experienced this? This change really needs to be looked at, a new version with this does no harm whatsoever |
|
Looks like i've stumbled upon this one too in Any progress on getting this in? as it's a complete deal breaker now in Rails 7 😢 |
|
Is there any progress on merging this PR? The latest version of the JSON gem is now 2.7.1 |
Considering there is no breaking change from json 2.1 to 2.3, I'm bumping the dependency to fix CVE-2020-10663