Effective immediately, 1.8.7 and 1.9.2 will be supported for security patches
until June 2014.
- Terence Lee (@hone02)
and Zachary Scott (@_zzak)
will assume maintainership.
- After the 6 month maintenance period, we can add more committers to extend
another 6 months.
We take security very seriously, if you find a vulnerability please report it
to firstname.lastname@example.org immediately. This mailing list is private and
reported problems will be published after a fix is released.
Please see ruby-lang.org/en/security for more information.
On Release Management
As I mentioned above, we will only be applying security patches and
incrementing the patch level.
We will not be releasing a patched version of 1.8.7 or 1.9.2 to ruby-lang.org.
However, you are free to repackage binaries from source.
Reason being, we don’t want any new tickets, as an official release will result
in continued responsibility of ruby-core to follow up on maintenance. Our team
resources are already low, and we want to encourage upgrades, not support
Why resurrect 1.8.7?
You may remember an announcement approximately 6 months ago that
While ruby-core will no longer resume maintenance of 1.8.7 or 1.9.2, Terence
and Zachary will support these versions for security maintenance as part of a
In the past we have supported vendors who wish to maintain legacy versions. In
2009 the maintenance of Ruby 1.8.6 was transfered to Engine Yard when they
Words of encouragement
We would like to take this chance to strongly encourage you to upgrade to a
supported version of Ruby as soon as possible. Many ruby-core members have put
countless hours into improving the performance and features of Ruby in 2.0+ and
we wish you would take advantage of it.
Thank you for your continued support and lets keep making Ruby better!
Posted by zzak on 17 Dec 2013Read more at the source