Skip to content

fix: require unitsdb ~> 2.2.5 (CVE-2026-85396 rubyzip path traversal) - #76

Merged
ronaldtse merged 1 commit into
mainfrom
fix/require-unitsdb-2.2.5
Sep 17, 2026
Merged

ronaldtse merged 1 commit into
mainfrom
fix/require-unitsdb-2.2.5

Conversation

@ronaldtse

Copy link
Copy Markdown
Contributor

Summary

Tightens the unitsdb dependency floor from ~> 2.2.4 to ~> 2.2.5 so that fresh resolves of unitsml cannot pick up the chain affected by the rubyzip path traversal vulnerability (CVE-2026-85396):

  • unitsdb 2.2.5 requires rubyzip ~> 3.4 (vulnerability affects rubyzip < 3.4.0)
  • ~> 2.2.4 still admitted unitsdb 2.2.4, which pins rubyzip ~> 2.3

Validated locally against unitsdb 2.2.5, lutaml-model 0.8.33, rubyzip 3.6.0: 456 examples, 0 failures; rubocop clean.

Testing

  • Full suite: 456 examples, 0 failures
  • rubocop unitsml.gemspec: no offenses

unitsdb 2.2.5 raises its rubyzip dependency to ~> 3.4, closing
the path traversal vulnerability in rubyzip < 3.4.0
(CVE-2026-85396). Tighten the floor so fresh resolves cannot
pick up the vulnerable unitsdb 2.2.4 / rubyzip 2.x chain.
@ronaldtse
ronaldtse merged commit cbf5c46 into main Sep 17, 2026
16 of 19 checks passed
@ronaldtse
ronaldtse deleted the fix/require-unitsdb-2.2.5 branch September 18, 2026 06:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant