Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think Rails 3 is _already_ security-fix only.

But I understand why they did it. And I sympathize. The Rails treadmill is a harsh regime.

I wonder if they're considering what the heck they are going to do when Rails 5 comes out (target: spring/summer of 2015. Less than 12 months) and Rails 3.x stops even receiving security updates. I mean, clearly they have the resources to backport security updates themselves that's not a problem -- it's just that they're still not quite in 'the modern world', they've just kept from falling even further behind.



We already have the app booting on 3.2; the goal is to try to get to 4.0 and track master fairly quickly. No one's eager to have to go through this whole process again in a year. ;)


Rails 3 is already only receiving security updates for "severe" issues, see http://rubyonrails.org/security/


thanks for that link!

While it says `/security`, it's actually the only link I know of with an updated list of how the maintenance policy applies to current versions.

I hadn't been able to find such before, only dated news/blog announcements, which can get out of date really quickly as fast as Rails goes.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: