3 ms·
If you love constant patching for the daily critical security holes, stick with Rails. If you love worrying where they have stuck yet another Yaml parser, and w
by static_typed 14y ago
If you love constant patching for the daily critical security holes, stick with Rails.
If you love worrying where they have stuck yet another Yaml parser, and where else they are eval-ing user supplied data, stick with Rails.
If you prefer a bit of an easier, less-stressful life, there is hope with many of the Perl, Python and PHP frameworks.
- squidsoup 14y agoLike the Django patch that was released yesterday? (https://www.djangoproject.com/weblog/2013/feb/19/security/ https://www.djangoproject.com/weblog/2013/feb/19/security/) The fact that the Rails team quickly responds to vulnerabilities should be reassuring not a disincentive to use the framework. All software is subject to vulnerabilities - the recent issues with YAML are a class of exploit common across many frameworks in different ecosystems (Django's TastyPie had a similar issue in the past).
- static_typed 14y agoYes, Django took a solid step to properly fix the underlying issue, rather than apply many small sticky-plasters over several days instead, leaving the same basic vector open in the meantime. In fact, the Django issue reported was posted on HN yesterday and the comments on that posting underline what I just said here. Remember - Python for Pros, Ruby to pose.
- slurgfest 14y agoI'm a big Python fan but that closing remark is just an incredibly obnoxious thing to say and is only going to feed the Python haters