Path to this page:
Subject: CVS commit: pkgsrc/lang
From: Takahiro Kambe
Date: 2023-04-01 11:08:51
Message id: 20230401090851.376BBFA81@cvs.NetBSD.org
Log Message:
lang/ruby30: update to 3.0.6
Ruby 3.0.6 Released Posted by usa on 30 Mar 2023
Ruby 3.0.6 has been released.
This release includes security fixes. Please check the topics below for
details.
* CVE-2023-28755: ReDoS vulnerability in URI
* CVE-2023-28756: ReDoS vulnerability in Time
This release also includes some bug fixes. See the GitHub releases for
further details.
After this release, we end the normal maintenance phase of Ruby 3.0, and
Ruby 3.0 enters the security maintenance phase. This means that we will no
longer backport any bug fixes to Ruby 3.0 except security fixes.
The term of the security maintenance phase is scheduled for a year. Ruby
3.0 reaches EOL and its official support ends by the end of the security
maintenance phase. Therefore, we recommend that you start to plan upgrade
to Ruby 3.1 or 3.2.
Files: