Skip to content

Update Ruby dependencies - #527

Merged
kieran-osgood-shopify merged 1 commit into
dependency-sweep/javascriptfrom
dependency-sweep/ruby
Oct 2, 2026
Merged

kieran-osgood-shopify merged 1 commit into
dependency-sweep/javascriptfrom
dependency-sweep/ruby

Conversation

@kieran-osgood-shopify

@kieran-osgood-shopify kieran-osgood-shopify commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

What changes are you making?

Scope

Second layer of the dependency-cleanup stack, based on the JavaScript/tooling layer.

  • Update ActiveSupport to 7.2.3.2, Addressable to 2.9.0, concurrent-ruby to 1.3.8, and JSON to 2.21.2.
  • Replace the concurrent-ruby cap that prevented security updates with a patched-version floor.
  • Keep JSON on the patched 2.x line rather than introducing an unrelated JSON 3 migration.
  • Preserve CocoaPods 1.15.2, xcodeproj 1.25.1, Ruby/Bundler versions, and all native pod versions.

Security and validation

  • The locked versions no longer match any of the nine baseline Ruby vulnerability ranges. Alerts resolve only after these dependencies reach the default branch and GitHub refreshes its graph.
  • A fresh OSV audit of all 46 locked gem packages reports no findings.
  • Frozen Bundler installation and Ruby tooling smoke checks pass, including ActiveSupport/CocoaPods loading, JSON round trips, and Addressable URI parsing.
  • Deployment-mode CocoaPods installation succeeds with all 87 pods; Podfile.lock is unchanged.
  • Native CI runs on this layer; the combined iOS/Android device sweep is performed from the completed stack tip.

Supersedes

Closes #447
Closes #460
Closes #494
Closes #507
Closes #525
Closes #526

These closure references are not proof of remediation; confirm the bot PRs and security alerts after landing the stack.

How to test

GIVEN the reviewer uses the repository's pinned Ruby environment and has configured the iOS sample for a development storefront

WHEN the reviewer reinstalls the sample's Ruby dependencies and CocoaPods, then opens sample/ios/ReactNative.xcworkspace and launches the sample

THEN dependency setup completes without logger, JSON, or gem-resolution errors, and the sample can load the catalog and open/dismiss checkout as on the base branch


PR Checklist

Important

Releasing a new version of the kit?


Tip

See the Contributing documentation for instructions on how to publish a new version of the library.

@kieran-osgood-shopify
kieran-osgood-shopify added this pull request to stack #528 September 17, 2026 10:06
@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Coverage Report

Lines Statements Branches Functions
Coverage: 99%
99.12% (227/229) 94.61% (123/130) 100% (67/67)

@kieran-osgood-shopify
kieran-osgood-shopify marked this pull request as ready for review October 1, 2026 10:16
@kieran-osgood-shopify
kieran-osgood-shopify requested a review from a team as a code owner October 1, 2026 10:16
@kieran-osgood-shopify
kieran-osgood-shopify removed this pull request from stack #528 October 1, 2026 10:53
@kieran-osgood-shopify
kieran-osgood-shopify added this pull request to stack #538 October 1, 2026 10:53
### Scope

Second layer of the dependency-cleanup stack, based on the JavaScript/tooling layer.

- Update ActiveSupport to 7.2.3.2, Addressable to 2.9.0, concurrent-ruby to 1.3.8, and JSON to 2.21.2.
- Replace the concurrent-ruby cap that prevented security updates with a patched-version floor.
- Keep JSON on the patched 2.x line rather than introducing an unrelated JSON 3 migration.
- Preserve CocoaPods 1.15.2, xcodeproj 1.25.1, Ruby/Bundler versions, and all native pod versions.

### Security and validation

- The locked versions no longer match any of the nine baseline Ruby vulnerability ranges. Alerts resolve only after these dependencies reach the default branch and GitHub refreshes its graph.
- A fresh OSV audit of all 46 locked gem packages reports no findings.
- Frozen Bundler installation and Ruby tooling smoke checks pass, including ActiveSupport/CocoaPods loading, JSON round trips, and Addressable URI parsing.
- Deployment-mode CocoaPods installation succeeds with all 87 pods; Podfile.lock is unchanged.
- Native CI runs on this layer; the combined iOS/Android device sweep is performed from the completed stack tip.

### Supersedes

Closes #447
Closes #460
Closes #494
Closes #507
Closes #525
Closes #526

These closure references are not proof of remediation; confirm the bot PRs and security alerts after landing the stack.

### How to test

**GIVEN** the reviewer uses the repository's pinned Ruby environment and has configured the iOS sample for a development storefront

**WHEN** the reviewer reinstalls the sample's Ruby dependencies and CocoaPods, then opens `sample/ios/ReactNative.xcworkspace` and launches the sample

**THEN** dependency setup completes without logger, JSON, or gem-resolution errors, and the sample can load the catalog and open/dismiss checkout as on the base branch

Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6
@kieran-osgood-shopify
kieran-osgood-shopify merged commit 9a965d7 into main Oct 2, 2026
15 checks passed
@kieran-osgood-shopify
kieran-osgood-shopify deleted the dependency-sweep/ruby branch October 2, 2026 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants