mirror of
https://github.com/react/react-native.git
synced 2026-09-28 05:13:06 +08:00
Summary: Pull Request resolved: https://github.com/react/react-native/pull/57355 Changelog: [INTERNAL] Fix Dependabot security update for concurrent-ruby in react-native The Dependabot GitHub Action on `react/react-native` `main` has been failing repeatedly because of `concurrent-ruby`. A security advisory marks `concurrent-ruby < 1.3.7` as affected (patched in `1.3.7`), but all three RN Gemfiles pin `gem 'concurrent-ruby', '<= 1.3.4'`. Dependabot cannot satisfy the advisory under that pin, so it opens a security PR to bump to `1.3.7` and then, on every subsequent run, reports `pull_request_exists_for_latest_version` as a hard error — failing the check and regenerating the internal CI task. The `<= 1.3.4` upper bound was originally added because `concurrent-ruby 1.3.5` dropped its `logger` dependency, which broke older `activesupport`/CocoaPods setups. That cause is already mitigated: every Gemfile now explicitly lists `gem 'logger'`. The upper-bound pin is therefore obsolete. This change relaxes the constraint from `<= 1.3.4` to `>= 1.3.7` in all three Gemfiles (root, `private/helloworld`, `packages/rn-tester`) and updates the two corresponding `Gemfile.lock` files to resolve `concurrent-ruby 1.3.7`. `1.3.7` introduces no new transitive dependencies over `1.3.4`, so no other lockfile entries change. With the advisory satisfied on `main`, Dependabot stops recreating the security PR and the recurring check failure stops. Reviewed By: javache Differential Revision: D109967250 fbshipit-source-id: 88f702bc6677053456557591cfd703776bb6c018
23 lines
830 B
Ruby
23 lines
830 B
Ruby
source 'https://rubygems.org'
|
|
|
|
# You may use http://rbenv.org/ or https://rvm.io/ to install and use this version
|
|
ruby ">= 2.6.10"
|
|
|
|
# concurrent-ruby >= 1.3.5 no longer requires 'logger', and activesupport 6.1.x
|
|
# references Logger without requiring it, so `bundle exec pod` crashes with
|
|
# "uninitialized constant ActiveSupport::LoggerThreadSafeLevel::Logger". A bare
|
|
# `gem 'logger'` is not enough because bundler does not auto-require Gemfile gems;
|
|
# require it here so it is loaded before cocoapods loads active_support.
|
|
require 'logger'
|
|
|
|
gem 'cocoapods', '~> 1.13', '!= 1.15.0', '!= 1.15.1'
|
|
gem 'activesupport', '>= 6.1.7.5', '< 7.1.0'
|
|
gem 'xcodeproj', '< 1.26.0'
|
|
gem 'concurrent-ruby', '>= 1.3.7'
|
|
|
|
# Ruby 3.4.0 has removed some libraries from the standard library.
|
|
gem 'bigdecimal'
|
|
gem 'logger'
|
|
gem 'benchmark'
|
|
gem 'mutex_m'
|