GitHub
06/05/2026, 7:50 AMrel-20250625) to 3.4.7 (rel-20251122) to resolve security vulnerabilities reported in PACT-6860 / CC-39510
• Ruby 3.4.7 ships zlib-3.2.1 and uri-1.0.4 as default gems, replacing the vulnerable zlib-3.1.1 and uri-0.13.2
• Updates macOS asset names (osx-* → macos-*) to match renamed assets in rel-20251122
• Updates Windows sed patch line for stub_specification.rb (line 37 → 41, which moved in Ruby 3.4)
• Bumps pinned native gem versions to their pre-compiled counterparts for Ruby 3.4: json 2.7.2→2.16.0, bigdecimal 3.1.5→3.1.8, fiddle 1.1.2→1.1.8, io-console 0.7.1→0.8.1
• Regenerates packaging/Gemfile.lock with Ruby 3.4 / Bundler 2.7.2
Context
A customer's vulnerability scanner flagged the following default gems bundled in the Pact runtime:
• /usr/local/pact/lib/ruby/lib/ruby/gems/3.3.0/specifications/default/zlib-3.1.1.gemspec
• /usr/local/pact/lib/ruby/lib/ruby/gems/3.3.0/specifications/default/uri-0.13.2.gemspec
These are default gems baked into the Traveling Ruby runtime — they cannot be overridden via Bundler. Upgrading to Ruby 3.4.7 is the only clean fix.
Test plan
• CI build passes for all platforms (linux-x86_64, linux-arm64, macos-x86_64, macos-arm64, windows-x86_64)
• Verify zlib and uri gemspec versions in the packaged output
• Smoke test the standalone binaries on each platform
🤖 Generated with Claude Code
pact-foundation/pact-standaloneGitHub
06/08/2026, 1:46 PM