3 ms·
Accusing the ruby-core folks of a lack of candor in their handling of the previous round of vulnerabilities isn't really fair. Once the issues were effectively
by rcoder 18y ago
Accusing the ruby-core folks of a lack of candor in their handling of the previous round of vulnerabilities isn't really fair. Once the issues were effectively documented and explained, they released updated versions of Ruby 1.8.6 and 1.8.7 quite quickly.
The problem was simple that the core team doesn't use Rails, so they didn't test the patches they produced with non-trivial Rails apps. When other people did that testing, they got segfaults, freaked out, and basically tried to tell the core team that their release process was shit, and that they should let a bunch of outsiders tell them how to manage their releases.
Personally, I was embarrassed to be part of the English-speaking Ruby community during that entire episode.
- donw 18y agoI think that there are problems on both sides of this. On the Ruby side, it makes a lot of sense to have Rails be part of the testing process, simply because it is such a prominent Ruby application framework. This doesn't mean that the Ruby people need to fix Rails, just that they should be aware when a core update breaks it. On the Rails side, a bit more understanding, and a willingness to jump in and help, would go a long way.