From 7ebf32cd7ade9fe8cd8971b78a800b2cc3bef9a3 Mon Sep 17 00:00:00 2001 From: Nathan Woodhull Date: Tue, 15 Sep 2026 13:07:28 -0400 Subject: [PATCH 1/2] fix(deps): allow json 3 The explicit json dependency added in #115 was meant as a CVE floor, but ~> 2.19 also caps consumers below 3.0. The SDK only uses JSON.generate and JSON.parse, which are unchanged in json 3. Co-Authored-By: Claude Opus 5 --- CHANGELOG.md | 3 +++ langfuse.gemspec | 2 +- 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1523bfb..0aa7bfe 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +### Changed +- Allow json 3.x while keeping the CVE-2026-54696 floor. + ## [0.12.2] - 2026-09-04 ### Fixed diff --git a/langfuse.gemspec b/langfuse.gemspec index c097241..c88c386 100644 --- a/langfuse.gemspec +++ b/langfuse.gemspec @@ -37,7 +37,7 @@ Gem::Specification.new do |spec| # json is used directly at runtime (api_client, read_api, score_client) and was only # constrained transitively via faraday. Declared explicitly with a >= 2.19.9 floor so # consumers cannot resolve json affected by CVE-2026-54696. - spec.add_dependency "json", "~> 2.19", ">= 2.19.9" + spec.add_dependency "json", ">= 2.19.9", "< 4" # Runtime dependencies - Concurrency (for SWR caching) # concurrent-ruby floor raised to 1.3.7 to exclude CVE-2026-54904/54905/54906. From b1fc30642c8ce31c330824c484eeb7bc437e5887 Mon Sep 17 00:00:00 2001 From: kadekillary Date: Tue, 15 Sep 2026 22:53:22 -0600 Subject: [PATCH 2/2] fix(deps): require JSON 3 compatible Faraday and test both majors --- .github/workflows/ci.yml | 28 ++++++++++++++++++++++++++-- .gitignore | 1 + CHANGELOG.md | 2 +- Gemfile | 10 +--------- Gemfile.lock | 13 ++++++++----- gemfiles/test.gemfile | 17 +++++++++++++++++ langfuse.gemspec | 4 ++-- 7 files changed, 56 insertions(+), 19 deletions(-) create mode 100644 gemfiles/test.gemfile diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index de5594d..4311ab2 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -53,6 +53,30 @@ jobs: flags: unittests fail_ci_if_error: false + test-json3: + name: Test JSON 3 (Ruby ${{ matrix.ruby }}) + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + ruby: ['3.2', '3.3', '3.4'] + env: + BUNDLE_GEMFILE: gemfiles/test.gemfile + JSON_VERSION: '~> 3.0' + + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Set up Ruby + uses: ruby/setup-ruby@v1 + with: + ruby-version: ${{ matrix.ruby }} + bundler-cache: true + + - name: Run tests + run: bundle exec rspec + lint: name: Lint (Rubocop) runs-on: ubuntu-latest @@ -72,13 +96,13 @@ jobs: ci-success: name: CI Success - needs: [test, lint] + needs: [test, test-json3, lint] runs-on: ubuntu-latest if: always() steps: - name: Check all jobs run: | - if [ "${{ needs.test.result }}" != "success" ] || [ "${{ needs.lint.result }}" != "success" ]; then + if [ "${{ needs.test.result }}" != "success" ] || [ "${{ needs.test-json3.result }}" != "success" ] || [ "${{ needs.lint.result }}" != "success" ]; then echo "One or more CI jobs failed" exit 1 fi diff --git a/.gitignore b/.gitignore index c090fa5..8ef86a9 100644 --- a/.gitignore +++ b/.gitignore @@ -7,6 +7,7 @@ coverage/ # Bundler .bundle/ vendor/bundle/ +gemfiles/*.lock # Gem build artifacts *.gem diff --git a/CHANGELOG.md b/CHANGELOG.md index 0aa7bfe..52ab45c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] ### Changed -- Allow json 3.x while keeping the CVE-2026-54696 floor. +- Allow JSON 3.x and require Faraday 2.14.4 or newer for compatible response parsing (#123). ## [0.12.2] - 2026-09-04 diff --git a/Gemfile b/Gemfile index 600611b..68defb1 100644 --- a/Gemfile +++ b/Gemfile @@ -1,17 +1,9 @@ # frozen_string_literal: true -source "https://rubygems.org" - -# Specify your gem's dependencies in langfuse.gemspec -gemspec +eval_gemfile "gemfiles/test.gemfile" # Development dependencies group :development, :test do - gem "dotenv", "~> 2.8" - gem "rake", "~> 13.0" - gem "rspec", "~> 3.12" gem "rubocop", "~> 1.50" gem "rubocop-rspec", "~> 2.20" - gem "simplecov", "~> 0.22" - gem "webmock", "~> 3.18" end diff --git a/Gemfile.lock b/Gemfile.lock index 90b4695..60e7da1 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -4,9 +4,9 @@ PATH langfuse-rb (0.12.2) base64 (~> 0.2) concurrent-ruby (>= 1.3.7, < 2.0) - faraday (>= 2.14.3, < 3) + faraday (>= 2.14.4, < 3) faraday-retry (>= 1.0, < 3.0) - json (~> 2.19, >= 2.19.9) + json (>= 2.19.9, < 4) mustache (~> 1.1) opentelemetry-api (~> 1.2) opentelemetry-common (~> 0.21) @@ -28,7 +28,7 @@ GEM diff-lcs (1.6.2) docile (1.4.1) dotenv (2.8.1) - faraday (2.14.3) + faraday (2.14.4) faraday-net_http (>= 2.0, < 3.5) json logger @@ -36,7 +36,10 @@ GEM net-http (>= 0.5.0) faraday-retry (2.4.0) faraday (~> 2.0) - google-protobuf (4.33.4) + google-protobuf (4.33.4-arm64-darwin) + bigdecimal + rake (>= 13) + google-protobuf (4.33.4-x86_64-linux-gnu) bigdecimal rake (>= 13) googleapis-common-protos-types (1.22.0) @@ -129,7 +132,7 @@ GEM unicode-display_width (3.2.0) unicode-emoji (~> 4.1) unicode-emoji (4.2.0) - uri (1.0.4) + uri (1.1.1) webmock (3.25.1) addressable (>= 2.8.0) crack (>= 0.3.2) diff --git a/gemfiles/test.gemfile b/gemfiles/test.gemfile new file mode 100644 index 0000000..12e841d --- /dev/null +++ b/gemfiles/test.gemfile @@ -0,0 +1,17 @@ +# frozen_string_literal: true + +source "https://rubygems.org" + +# Specify your gem's dependencies in langfuse.gemspec +gemspec path: ".." + +# Test JSON compatibility independently of development tools' dependency constraints. +gem "json", ENV["JSON_VERSION"] if ENV["JSON_VERSION"] + +group :development, :test do + gem "dotenv", "~> 2.8" + gem "rake", "~> 13.0" + gem "rspec", "~> 3.12" + gem "simplecov", "~> 0.22" + gem "webmock", "~> 3.18" +end diff --git a/langfuse.gemspec b/langfuse.gemspec index c88c386..cda3483 100644 --- a/langfuse.gemspec +++ b/langfuse.gemspec @@ -29,9 +29,9 @@ Gem::Specification.new do |spec| spec.require_paths = ["lib"] # Runtime dependencies - HTTP & Templating - # faraday floor raised to 2.14.3 to exclude CVE-2026-33637 and CVE-2026-54297. + # Faraday 2.14.4 adds JSON 3 compatibility and includes the fixes for CVE-2026-33637 and CVE-2026-54297. # This drops Faraday 1.x support; Faraday 2.x needs Ruby >= 3.0, satisfied by our >= 3.2.0 floor. - spec.add_dependency "faraday", ">= 2.14.3", "< 3" + spec.add_dependency "faraday", ">= 2.14.4", "< 3" spec.add_dependency "faraday-retry", ">= 1.0", "< 3.0" spec.add_dependency "mustache", "~> 1.1" # json is used directly at runtime (api_client, read_api, score_client) and was only