Repository navigation
Update Ruby dependencies - #527
Merged
kieran-osgood-shopify merged 1 commit intoOct 2, 2026
Merged
Conversation
kieran-osgood-shopify
added this pull request to stack #528
September 17, 2026 10:06
kieran-osgood-shopify
force-pushed
the
dependency-sweep/ruby
branch
from
September 18, 2026 12:47
ffbdb04 to
5aedf6e
Compare
kieran-osgood-shopify
force-pushed
the
dependency-sweep/ruby
branch
from
September 29, 2026 13:25
5aedf6e to
2929f18
Compare
kieran-osgood-shopify
marked this pull request as ready for review
October 1, 2026 10:16
kieran-osgood-shopify
force-pushed
the
dependency-sweep/ruby
branch
from
October 1, 2026 10:52
2929f18 to
e2a6f47
Compare
kieran-osgood-shopify
removed this pull request from stack #528
October 1, 2026 10:53
kieran-osgood-shopify
added this pull request to stack #538
October 1, 2026 10:53
kiftio
approved these changes
Oct 1, 2026
### Scope Second layer of the dependency-cleanup stack, based on the JavaScript/tooling layer. - Update ActiveSupport to 7.2.3.2, Addressable to 2.9.0, concurrent-ruby to 1.3.8, and JSON to 2.21.2. - Replace the concurrent-ruby cap that prevented security updates with a patched-version floor. - Keep JSON on the patched 2.x line rather than introducing an unrelated JSON 3 migration. - Preserve CocoaPods 1.15.2, xcodeproj 1.25.1, Ruby/Bundler versions, and all native pod versions. ### Security and validation - The locked versions no longer match any of the nine baseline Ruby vulnerability ranges. Alerts resolve only after these dependencies reach the default branch and GitHub refreshes its graph. - A fresh OSV audit of all 46 locked gem packages reports no findings. - Frozen Bundler installation and Ruby tooling smoke checks pass, including ActiveSupport/CocoaPods loading, JSON round trips, and Addressable URI parsing. - Deployment-mode CocoaPods installation succeeds with all 87 pods; Podfile.lock is unchanged. - Native CI runs on this layer; the combined iOS/Android device sweep is performed from the completed stack tip. ### Supersedes Closes #447 Closes #460 Closes #494 Closes #507 Closes #525 Closes #526 These closure references are not proof of remediation; confirm the bot PRs and security alerts after landing the stack. ### How to test **GIVEN** the reviewer uses the repository's pinned Ruby environment and has configured the iOS sample for a development storefront **WHEN** the reviewer reinstalls the sample's Ruby dependencies and CocoaPods, then opens `sample/ios/ReactNative.xcworkspace` and launches the sample **THEN** dependency setup completes without logger, JSON, or gem-resolution errors, and the sample can load the catalog and open/dismiss checkout as on the base branch Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6
kieran-osgood-shopify
force-pushed
the
dependency-sweep/ruby
branch
from
October 2, 2026 09:30
e2a6f47 to
3c964dc
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes are you making?
Scope
Second layer of the dependency-cleanup stack, based on the JavaScript/tooling layer.
Security and validation
Supersedes
Closes #447
Closes #460
Closes #494
Closes #507
Closes #525
Closes #526
These closure references are not proof of remediation; confirm the bot PRs and security alerts after landing the stack.
How to test
GIVEN the reviewer uses the repository's pinned Ruby environment and has configured the iOS sample for a development storefront
WHEN the reviewer reinstalls the sample's Ruby dependencies and CocoaPods, then opens
sample/ios/ReactNative.xcworkspaceand launches the sampleTHEN dependency setup completes without logger, JSON, or gem-resolution errors, and the sample can load the catalog and open/dismiss checkout as on the base branch
PR Checklist
Important
Releasing a new version of the kit?
package.jsonfile.Tip
See the Contributing documentation for instructions on how to publish a new version of the library.