Skip to content

deps: update concurrent-ruby for dependabot alerts - #9

Merged
unattributed merged 2 commits into
mainfrom
security/update-concurrent-ruby-1-3-7
Jun 29, 2026
Merged

deps: update concurrent-ruby for dependabot alerts#9
unattributed merged 2 commits into
mainfrom
security/update-concurrent-ruby-1-3-7

Conversation

@unattributed

Copy link
Copy Markdown
Owner

Summary

  • Updates concurrent-ruby from 1.3.6 to 1.3.7 in Gemfile.lock.
  • Addresses the open Dependabot alerts for CVE-2026-54904, CVE-2026-54905, and CVE-2026-54906, all of which affect concurrent-ruby versions prior to 1.3.7.
  • Adds pull request validation for the Jekyll Pages workflow while keeping deployment restricted to pushes to main.

Validation

  • GitHub Actions should run the Jekyll build on this pull request.
  • After merge, Dependabot should close the three open alerts once the dependency graph refreshes.

Security

  • No runtime site behavior changes.
  • No JavaScript or frontend dependency additions.
  • Dependency lockfile update only, plus CI validation coverage.

@unattributed
unattributed merged commit 6bef6eb into main Jun 29, 2026
3 checks passed
@unattributed
unattributed deleted the security/update-concurrent-ruby-1-3-7 branch June 29, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant