TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Rails 3.0.20 and 2.3.16 have been released

68 点作者 tamersalama超过 12 年前

3 条评论

speleding超过 12 年前
As far as I can tell the latest Rails version (3.2.11) is not affected. Of course, I only noticed this after frantically updating my gems. Sigh.
评论 #5131020 未加载
epochwolf超过 12 年前
Oh joy. We just patch the last bug in 2.3. My manager will not be happy.
评论 #5131956 未加载
评论 #5131754 未加载
评论 #5131245 未加载
评论 #5131157 未加载
static_typed超过 12 年前
Given we are still seeing more security issues with Rails, shouldn't the developers down tools for 5 mins to stop with the shiny-shiny, and maybe rewalk the codebase, the dependencies they set, and review things?<p>Yes, they are quick to band-aid the overall problem, and push out yet another version bump, but, no one other there seems to really grasp the nettle and admit too much auto, too much magic, too much opinionated design has meant a framework with more holes than swiss cheese. We have only just started to see the trickle of reported issues, before the flood.<p>Ironically, we had a call this morning from a customer that there rails app server has been compromised, despite diligently patching and updating.<p>I would rather see one better update to Rails for the release versions, arising from a proper audit, proactively closing the windows left from before, rather than shutting one each time it is reported.
评论 #5131050 未加载
评论 #5131247 未加载
评论 #5131983 未加载
评论 #5131534 未加载
评论 #5131132 未加载
评论 #5131642 未加载