Rails 3.2.13, 3.1.12, and 2.3.18 have been released
weblog.rubyonrails.org
weblog.rubyonrails.org
Anyway, Rails is now more secure than it was yesterday, that's a great thing so yeah, thank you very much.
You're making Rails safer, each day, bit by bit.
edit: I actually found in the changelog : Feb 24, 2013:
Sikachu: Rails 3.2.x is now compatible with Ruby 2.0.0
thanks
http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/...
Is this indicative of the time the vulnerability was reported?
Is it normal procedure for a patch for a security vulnerability to delayed for 36 days?
Yet another freak'n patch again. Ridiculous!
At this rate, you might as well just make an official "patch Monday", so that we can expect to have weekly security bugs fixed.
I am using test unit and this seems to be related to mini test so I am not sure what is going on?
If that's not the same as yours, please file an issue.
If this causes problems and you want a quick fix, this gist does the job.
Not sure if this is a rails, bundler, or rubygems issue, at this point.
Yuck.
The 3 versions patched are not forks. They're just different versions of Rails. In three years, they'll probably still support about 3 versions and drop support for older versions once they hit a certain age.
You can find the exact maintenance policy here: http://weblog.rubyonrails.org/2013/2/24/maintenance-policy-f...
You can check the upgrading guide for more details about what's changed, and a third party is selling an ebook that has a ton of good info as well.
We're also starting to use verb-matchers in the routes file, but that's going to be a bit more painful to deal with…