I don't blame the authors for discontinuing old branches (1.2.x), but it makes me hesitant using Sinatra for a production website that's meant to be there for >= 2 years (though is an eon in IT).
I don't blame the authors for discontinuing old branches (1.2.x), but it makes me hesitant using Sinatra for a production website that's meant to be there for >= 2 years (though is an eon in IT).
Also, the Sinatra code base is pretty small, so just because it's no longer officially maintained doesn't mean you can't run Sinatra 1.2.0. All security issues we have seen so far have all been in Sinatra dependencies (namely Rack) and never in Sinatra itself.
If you are stuck on an unmaintained Ruby version that's a way bigger issue than being stuck on an unmaintained Sinatra version. You should not run Ruby 1.8.6 in production for security reasons.
Many projects out there follow the two maintained feature versions approach, like Rails. How many versions of Sinatra should see regular releases? What about 1.1.x? Or 0.9.x?
It has also been announced with the 1.3.0 release that 1.2.x will be continued until the 1.4.0 release.
Being stuck on 1.2.x is pretty bad, as it still ships without rack-protection.
It's just the logical step to get rid of old deprecated stuff.
I haven't checked, but for starters you possibly could look at the download size.