Skip to content

Bump msgpack from 1.8.1 to 1.8.2#4659

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/bundler/msgpack-1.8.2
Closed

Bump msgpack from 1.8.1 to 1.8.2#4659
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/bundler/msgpack-1.8.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 10, 2026

Copy link
Copy Markdown
Contributor

Bumps msgpack from 1.8.1 to 1.8.2.

Changelog

Sourced from msgpack's changelog.

2026-06-09 1.8.2

  • Fix Buffer#clear to properly reset memory chunks before adding them back to the pool. This could have caused data to leak across buffers when using the MessagePack::Buffer API directly. [CVE-PENDING].
Commits

@dependabot dependabot Bot added dependencies ruby Pull requests that update Ruby code labels Jun 10, 2026
Bumps [msgpack](https://github.com/msgpack/msgpack-ruby) from 1.8.1 to 1.8.2.
- [Changelog](https://github.com/msgpack/msgpack-ruby/blob/master/ChangeLog)
- [Commits](msgpack/msgpack-ruby@v1.8.1...v1.8.2)

---
updated-dependencies:
- dependency-name: msgpack
  dependency-version: 1.8.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/bundler/msgpack-1.8.2 branch from 4ec3519 to fb6d2c5 Compare June 10, 2026 08:15
@dependabot @github

dependabot Bot commented on behalf of github Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #4660.

@dependabot dependabot Bot closed this Jun 11, 2026
@dependabot dependabot Bot deleted the dependabot/bundler/msgpack-1.8.2 branch June 11, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant