This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 25d
Productivity & Wikis
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
hotwire
kanban
rails
ruby
Affected surfaces
deps
Summary
AI summaryCVE-2026-54522 addressed by bumping msgpack and adds SJC staging nodes.
Full changelog
What's Changed
- Bump concurrent-ruby from 1.3.6 to 1.3.7 by @dependabot[bot] in https://github.com/basecamp/fizzy/pull/2948
- Bump
crassfor multiple security fixes by @rosa in https://github.com/basecamp/fizzy/pull/2950 - Bump
msgpackto address CVE-2026-54522 by @rosa in https://github.com/basecamp/fizzy/pull/2953 - Add SJC staging nodes. by @Ladybiss in https://github.com/basecamp/fizzy/pull/2952
- Serialize card numbering with a per-account row lock by @rosa in https://github.com/basecamp/fizzy/pull/2954
Full Changelog: https://github.com/basecamp/fizzy/compare/[email protected]@e9c30a0
Security Fixes
- CVE-2026-54522 — addressed by bumping msgpack
- Multiple security fixes applied via crass dependency bump
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]