Skip to content
This repository has been archived by the owner on Dec 22, 2022. It is now read-only.

Rails 4.2 is unsupported release #2015

Open
pgwillia opened this issue Jun 16, 2020 · 1 comment
Open

Rails 4.2 is unsupported release #2015

pgwillia opened this issue Jun 16, 2020 · 1 comment

Comments

@pgwillia
Copy link
Member

Describe the bug
When a release series is no longer supported, it's your own responsibility to deal with bugs and security issues. We [Rails] may provide backports of the fixes and publish them to git, however there will be no new versions released. If you are not comfortable maintaining your own versions, you should upgrade to a supported version. https://guides.rubyonrails.org/maintenance_policy.html

Expected behavior
We should be on a release series that is at least getting security patches. https://guides.rubyonrails.org/maintenance_policy.html

Additional context
Github is warning us about a XSS vulnerability in ActionView. Currently we're not affected but a fix would require a monkey patch rather than accepting a version bump.

@pgwillia
Copy link
Member Author

Rails 4.2 locks bundler <2.0

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

1 participant