This release includes 1 security fix for security teams reviewing exposed deployments.
Published 21d
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
hotwire
kanban
rails
ruby
Affected surfaces
deps
Summary
AI summarySecurity fix for CVE-2026-54696 in the json dependency.
Full changelog
What's Changed
- Add fizzy_solid_cache_* metrics via vendored Yabeda exporter by @rosa in https://github.com/basecamp/fizzy/pull/2958
- Bump json to 2.20.0 (CVE-2026-54696) by @rosa in https://github.com/basecamp/fizzy/pull/2962
Full Changelog: https://github.com/basecamp/fizzy/compare/[email protected]@90a244a
Security Fixes
- CVE-2026-54696 — vulnerability in json dependency; upgraded to version 2.20.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]