Skip to content

bump activerecord to fix cve-2025-55193#55

Merged
bgentry merged 1 commit intomasterfrom
bg/dependabot-alert-fix
Feb 18, 2026
Merged

bump activerecord to fix cve-2025-55193#55
bgentry merged 1 commit intomasterfrom
bg/dependabot-alert-fix

Conversation

@bgentry
Copy link
Contributor

@bgentry bgentry commented Feb 18, 2026

Dependabot flagged activerecord in driver/riverqueue-activerecord/Gemfile.lock as vulnerable for versions >= 8.0, < 8.0.2.1 (CVE-2025-55193). This bumps it to resolve the issue.

Fixes https://github.com/riverqueue/riverqueue-ruby/security/dependabot/25

@bgentry bgentry requested a review from brandur February 18, 2026 01:32
Dependabot flagged `activerecord` in
`driver/riverqueue-activerecord/Gemfile.lock` as vulnerable for versions
`>= 8.0, < 8.0.2.1` (CVE-2025-55193). This bumps it to resolve the
issue.
@bgentry bgentry force-pushed the bg/dependabot-alert-fix branch from c739bf4 to 21100bb Compare February 18, 2026 01:43
Copy link
Contributor

@brandur brandur left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Must have missed this. Good catch.

@bgentry bgentry merged commit be2710b into master Feb 18, 2026
10 checks passed
@bgentry bgentry deleted the bg/dependabot-alert-fix branch February 18, 2026 02:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments