From dc3fa31996b4b58cfbf24ddcfd36ee30899c4180 Mon Sep 17 00:00:00 2001 From: Agustin Biagini Date: Thu, 17 Aug 2023 10:12:25 -0300 Subject: [PATCH] Bump json gem version Json <= 2.2 had a Critical security Issue. See: https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/ --- mercadopago.gemspec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mercadopago.gemspec b/mercadopago.gemspec index 71d3aa4..73371ed 100644 --- a/mercadopago.gemspec +++ b/mercadopago.gemspec @@ -20,7 +20,7 @@ Gem::Specification.new do |s| s.require_paths = ["lib"] # specify any dependencies here: - s.add_dependency 'json', '~> 1.4' + s.add_dependency 'json', '~> 2.3' s.add_dependency 'faraday', '~> 0.9' s.add_development_dependency 'pry', '~> 0.11.1' s.add_development_dependency 'rake', '~> 12.1'