Skip to content

Release v5.18.1#700

Closed
arpit-jn wants to merge 2 commits intomasterfrom
release/v5.18.1
Closed

Release v5.18.1#700
arpit-jn wants to merge 2 commits intomasterfrom
release/v5.18.1

Conversation

@arpit-jn
Copy link
Contributor

@arpit-jn arpit-jn commented Mar 11, 2026

Fixed

  • Fixed a bug where passing an array as a request payload would delete its contents, causing API calls with array parameters to silently send empty data. (#697)

Changed

  • Updated zache from 0.13.2 to 0.15.2
  • Updated jwt from 2.9.3 to 2.10.2
  • Updated addressable from 2.8.7 to 2.8.8

Security

  • Removed unused coveralls and irb dev dependencies, eliminating OS Command Injection vulnerability in thor introduced transitively via coveralls
  • Replaced dotenv-rails with standalone dotenv, removing the full Rails transitive dependency chain and resolving 5 XSS vulnerabilities in rails-html-sanitizer
  • Upgraded rexml to 3.4.4 (via simplecov-cobertura and webmock upgrades) to fix XML Entity Expansion vulnerability

@arpit-jn arpit-jn requested a review from a team as a code owner March 11, 2026 12:43
@arpit-jn
Copy link
Contributor Author

Closing this release PR. Will be making additional changes and create new release PR.

@arpit-jn arpit-jn closed this Mar 13, 2026
@arpit-jn arpit-jn deleted the release/v5.18.1 branch March 13, 2026 05:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant