Repository navigation
v1.4.0 - Security & Compatibility Update
What's New
Breaking Change: Ruby 3.0+ now required (was 2.5+)
Security Fixes
All 11 Dependabot vulnerabilities resolved:
- CVE-2015-4411: BSON DoS vulnerability
- CVE-2022-44566: ActiveRecord PostgreSQL adapter DoS
- CVE-2023-38037: ActiveSupport local file disclosure
- CVE-2025-55193: ActiveRecord ANSI escape injection
Dependency Updates
| Package | Old | New |
|---|---|---|
| ActiveRecord/ActiveSupport | 6.1.x | 7.2.3 |
| MongoDB Ruby Driver | 1.12.5 | 2.22.0 |
| BSON | 1.12.5 | 5.2.0 |
| RSpec | 2.x | 3.x |
Full Changelog
See CHANGELOG.md