Skip to content

Allow concurrent-ruby 1.3.x (CVE-2026-54906/54904 fixes blocked by ~> 1.1 pins) #474

Description

@log0u7

dynflow 2.0.1 pins concurrent-ruby ~> 1.1.3 (gemspec) and concurrent-ruby-edge ~> 0.6.0 (which itself pins concurrent-ruby ~> 1.1.6). Every dependent (Foreman, the smart-proxy plugins) therefore resolves a concurrent-ruby release vulnerable to CVE-2026-54906 and CVE-2026-54904 (both fixed in 1.3.7), with no resolver path to the fixed version.

The constraint chain is double:

  • dynflow.gemspec: concurrent-ruby ~> 1.1.3
  • dynflow.gemspec: concurrent-ruby-edge ~> 0.6.0 -> concurrent-ruby ~> 1.1.6
  • foreman Gemfile: concurrent-ruby-ext ~> 1.1.3 (ext releases only exist on the 1.1 line until 1.3.8)

All three have current releases supporting the 1.3 line: concurrent-ruby 1.3.8, edge 0.7.2 (supports ~> 1.3), ext 1.3.8.

Required to unblock the fixes (in dynflow):

  • gemspec: concurrent-ruby '>= 1.1.3', '< 2.0'
  • gemspec: concurrent-ruby-edge '~> 0.7.0'
  • Gemfile: concurrent-ruby-ext '~> 1.3.0'
  • lib/dynflow.rb: require 'logger' - concurrent-ruby 1.1 loaded logger as a side effect; 1.3 no longer does, so the global logger wiring in lib/dynflow.rb crashes with NameError on 1.3.x

Test evidence (ruby 3.3, concurrent-ruby 1.3.8 + edge 0.7.2 + ext 1.3.8): bundle resolves cleanly and 397 tests of the suite pass, including executor, dispatcher and polling tests. The full suite later hangs in the multi-executor dispatcher tests in our container environment; the same hang reproduces on master with concurrent-ruby 1.1.10 (progressing through fewer tests), so it is pre-existing and unrelated to the version bump.

A draft PR with the exact change is #473.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions