Files
react-native/Gemfile
Christoph Purrer 96d3f91124 Fix Dependabot security update for concurrent-ruby in react-native (#57355)
Summary:
Pull Request resolved: https://github.com/react/react-native/pull/57355

Changelog: [INTERNAL] Fix Dependabot security update for concurrent-ruby in react-native

The Dependabot GitHub Action on `react/react-native` `main` has been failing repeatedly because of `concurrent-ruby`. A security advisory marks `concurrent-ruby < 1.3.7` as affected (patched in `1.3.7`), but all three RN Gemfiles pin `gem 'concurrent-ruby', '<= 1.3.4'`. Dependabot cannot satisfy the advisory under that pin, so it opens a security PR to bump to `1.3.7` and then, on every subsequent run, reports `pull_request_exists_for_latest_version` as a hard error — failing the check and regenerating the internal CI task.

The `<= 1.3.4` upper bound was originally added because `concurrent-ruby 1.3.5` dropped its `logger` dependency, which broke older `activesupport`/CocoaPods setups. That cause is already mitigated: every Gemfile now explicitly lists `gem 'logger'`. The upper-bound pin is therefore obsolete.

This change relaxes the constraint from `<= 1.3.4` to `>= 1.3.7` in all three Gemfiles (root, `private/helloworld`, `packages/rn-tester`) and updates the two corresponding `Gemfile.lock` files to resolve `concurrent-ruby 1.3.7`. `1.3.7` introduces no new transitive dependencies over `1.3.4`, so no other lockfile entries change. With the advisory satisfied on `main`, Dependabot stops recreating the security PR and the recurring check failure stops.

Reviewed By: javache

Differential Revision: D109967250

fbshipit-source-id: 88f702bc6677053456557591cfd703776bb6c018
2026-07-14 10:57:04 -07:00

23 lines
830 B
Ruby

source 'https://rubygems.org'
# You may use http://rbenv.org/ or https://rvm.io/ to install and use this version
ruby ">= 2.6.10"
# concurrent-ruby >= 1.3.5 no longer requires 'logger', and activesupport 6.1.x
# references Logger without requiring it, so `bundle exec pod` crashes with
# "uninitialized constant ActiveSupport::LoggerThreadSafeLevel::Logger". A bare
# `gem 'logger'` is not enough because bundler does not auto-require Gemfile gems;
# require it here so it is loaded before cocoapods loads active_support.
require 'logger'
gem 'cocoapods', '~> 1.13', '!= 1.15.0', '!= 1.15.1'
gem 'activesupport', '>= 6.1.7.5', '< 7.1.0'
gem 'xcodeproj', '< 1.26.0'
gem 'concurrent-ruby', '>= 1.3.7'
# Ruby 3.4.0 has removed some libraries from the standard library.
gem 'bigdecimal'
gem 'logger'
gem 'benchmark'
gem 'mutex_m'