<#236 fix(security): upgrade Traveling Ruby to 3.4...
# pact-ruby-standalone
g
#236 fix(security): upgrade Traveling Ruby to 3.4.7 to remediate zlib and uri CVEs Pull request opened by Saup21 Summary • Upgrades bundled Ruby runtime from 3.3.9 (
rel-20250625
) to 3.4.7 (
rel-20251122
) to resolve security vulnerabilities reported in PACT-6860 / CC-39510 • Ruby 3.4.7 ships
zlib-3.2.1
and
uri-1.0.4
as default gems, replacing the vulnerable
zlib-3.1.1
and
uri-0.13.2
• Updates macOS asset names (
osx-*
→
macos-*
) to match renamed assets in
rel-20251122
• Updates Windows
sed
patch line for
stub_specification.rb
(line 37 → 41, which moved in Ruby 3.4) • Bumps pinned native gem versions to their pre-compiled counterparts for Ruby 3.4:
json
2.7.2→2.16.0,
bigdecimal
3.1.5→3.1.8,
fiddle
1.1.2→1.1.8,
io-console
0.7.1→0.8.1 • Regenerates
packaging/Gemfile.lock
with Ruby 3.4 / Bundler 2.7.2 Context A customer's vulnerability scanner flagged the following default gems bundled in the Pact runtime: •
/usr/local/pact/lib/ruby/lib/ruby/gems/3.3.0/specifications/default/zlib-3.1.1.gemspec
•
/usr/local/pact/lib/ruby/lib/ruby/gems/3.3.0/specifications/default/uri-0.13.2.gemspec
These are default gems baked into the Traveling Ruby runtime — they cannot be overridden via Bundler. Upgrading to Ruby 3.4.7 is the only clean fix. Test plan • CI build passes for all platforms (linux-x86_64, linux-arm64, macos-x86_64, macos-arm64, windows-x86_64) • Verify
zlib
and
uri
gemspec versions in the packaged output • Smoke test the standalone binaries on each platform 🤖 Generated with Claude Code pact-foundation/pact-standalone