hibernate-ogm
hibernate-ogm copied to clipboard
Bump json from 1.8.2 to 2.3.0 in /src/main/release-scripts
trafficstars
Bumps json from 1.8.2 to 2.3.0.
Changelog
Sourced from json's changelog.
2019-12-11 (2.3.0)
- Fix default of
create_additionsto always befalseforJSON(user_input)andJSON.parse(user_input, nil). Note thatJSON.loadremains with defaulttrueand is meant for internal serialization of trusted data. [CVE-2020-10663]- Fix passing args all #to_json in json/add/*.
- Fix encoding issues
- Fix issues of keyword vs positional parameter
- Fix JSON::Parser against bigdecimal updates
- Bug fixes to JRuby port
2019-02-21 (2.2.0)
- Adds support for 2.6 BigDecimal and ruby standard library Set datetype.
2017-04-18 (2.1.0)
- Allow passing of
decimal_classoption to specify a class as which to parse JSON float numbers.2017-03-23 (2.0.4)
- Raise exception for incomplete unicode surrogates/character escape sequences. This problem was reported by Daniel Gollahon (dgollahon).
- Fix arbitrary heap exposure problem. This problem was reported by Ahmad Sherif (ahmadsherif).
2017-01-12 (2.0.3)
- Set
required_ruby_versionto 1.9- Some small fixes
2016-07-26 (2.0.2)
- Specify
required_ruby_versionfor json_pure.- Fix issue #295 failure when parsing frozen strings.
2016-07-01 (2.0.1)
- Fix problem when requiring json_pure and Parser constant was defined top level.
- Add
RB_GC_GUARDto avoid possible GC problem via Pete Johns.- Store
current_nestingon stack by Aaron Patterson.2015-09-11 (2.0.0)
- Now complies to newest JSON RFC 7159.
- Implements compatibiliy to ruby 2.4 integer unification.
- Drops support for old rubies whose life has ended, that is rubies < 2.0. Also see https://www.ruby-lang.org/en/news/2014/07/01/eol-for-1-8-7-and-1-9-2/
- There were still some mentions of dual GPL licensing in the source, but JSON has just the Ruby license that itself includes an explicit dual-licensing clause that allows covered software to be distributed under the terms of the Simplified BSD License instead for all ruby versions >= 1.9.3. This is however a GPL compatible license according to the Free Software Foundation. I changed these mentions to be consistent with the Ruby license setting in the gemspec files which were already correct now.
Commits
92cf5c4v2.3.0579ae85Add some more recent jrubyacabfebMake tests green on jrubyc194360Update travis config49317c1Ignore log filesd84439fMerge pull request #391 from headius/prep_2.3.038f68d1Bump versions for 2.3.0.40524a9Merge pull request #390 from flori/relax-test-unit87379e6relax test-unit version for old ruby05de02fMerge branch 'zenspider-zenspider/ruby-2.7'- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.