dynflow 2.0.1 pins concurrent-ruby ~> 1.1.3 (gemspec) and concurrent-ruby-edge ~> 0.6.0 (which itself pins concurrent-ruby ~> 1.1.6). Every dependent (Foreman, the smart-proxy plugins) therefore resolves a concurrent-ruby release vulnerable to CVE-2026-54906 and CVE-2026-54904 (both fixed in 1.3.7), with no resolver path to the fixed version.
The constraint chain is double:
- dynflow.gemspec: concurrent-ruby ~> 1.1.3
- dynflow.gemspec: concurrent-ruby-edge ~> 0.6.0 -> concurrent-ruby ~> 1.1.6
- foreman Gemfile: concurrent-ruby-ext ~> 1.1.3 (ext releases only exist on the 1.1 line until 1.3.8)
All three have current releases supporting the 1.3 line: concurrent-ruby 1.3.8, edge 0.7.2 (supports ~> 1.3), ext 1.3.8.
Required to unblock the fixes (in dynflow):
- gemspec: concurrent-ruby '>= 1.1.3', '< 2.0'
- gemspec: concurrent-ruby-edge '~> 0.7.0'
- Gemfile: concurrent-ruby-ext '~> 1.3.0'
- lib/dynflow.rb: require 'logger' - concurrent-ruby 1.1 loaded logger as a side effect; 1.3 no longer does, so the global logger wiring in lib/dynflow.rb crashes with NameError on 1.3.x
Test evidence (ruby 3.3, concurrent-ruby 1.3.8 + edge 0.7.2 + ext 1.3.8): bundle resolves cleanly and 397 tests of the suite pass, including executor, dispatcher and polling tests. The full suite later hangs in the multi-executor dispatcher tests in our container environment; the same hang reproduces on master with concurrent-ruby 1.1.10 (progressing through fewer tests), so it is pre-existing and unrelated to the version bump.
A draft PR with the exact change is #473.
dynflow 2.0.1 pins concurrent-ruby ~> 1.1.3 (gemspec) and concurrent-ruby-edge ~> 0.6.0 (which itself pins concurrent-ruby ~> 1.1.6). Every dependent (Foreman, the smart-proxy plugins) therefore resolves a concurrent-ruby release vulnerable to CVE-2026-54906 and CVE-2026-54904 (both fixed in 1.3.7), with no resolver path to the fixed version.
The constraint chain is double:
All three have current releases supporting the 1.3 line: concurrent-ruby 1.3.8, edge 0.7.2 (supports ~> 1.3), ext 1.3.8.
Required to unblock the fixes (in dynflow):
Test evidence (ruby 3.3, concurrent-ruby 1.3.8 + edge 0.7.2 + ext 1.3.8): bundle resolves cleanly and 397 tests of the suite pass, including executor, dispatcher and polling tests. The full suite later hangs in the multi-executor dispatcher tests in our container environment; the same hang reproduces on master with concurrent-ruby 1.1.10 (progressing through fewer tests), so it is pre-existing and unrelated to the version bump.
A draft PR with the exact change is #473.