2019 Archives

Ruby 2.7.0 Released

We are pleased to announce the release of Ruby 2.7.0.

Continue Reading...

Ruby 2.7.0-rc2 Released

Continue Reading...

Ruby 2.7.0-rc1 Released

Continue Reading...

Separation of positional and keyword arguments in Ruby 3.0

This article explains the planned incompatibility of keyword arguments in Ruby 3.0

Continue Reading...

Ruby 2.7.0-preview3 Released

We are pleased to announce the release of Ruby 2.7.0-preview3.

Continue Reading...

Ruby 2.7.0-preview2 Released

We are pleased to announce the release of Ruby 2.7.0-preview2.

Continue Reading...

2020 Fukuoka Ruby Award Competition - Entries to be judged by Matz

Dear Ruby Enthusiasts,

Continue Reading...

Ruby 2.4.9 Released

Ruby 2.4.9 has been released.

Continue Reading...

CVE-2019-16201: Regular Expression Denial of Service vulnerability of WEBrick's Digest access authentication

Regular expression denial of service vulnerability of WEBrick’s Digest authentication module was found. An attacker can exploit this vulnerability to cause an effective denial of service against a WEBrick service.

Continue Reading...

Ruby 2.6.5 Released

Ruby 2.6.5 has been released.

Continue Reading...

Ruby 2.5.7 Released

Ruby 2.5.7 has been released.

Continue Reading...

Ruby 2.4.8 Released

Ruby 2.4.8 has been released.

Continue Reading...

CVE-2019-15845: A NUL injection vulnerability of File.fnmatch and File.fnmatch?

A NUL injection vulnerability of Ruby built-in methods (File.fnmatch and File.fnmatch?) was found. An attacker who has the control of the path pattern parameter could exploit this vulnerability to make path matching pass despite the intention of the program author. CVE-2019-15845 has been assigned to this vulnerability.

Continue Reading...

CVE-2019-16254: HTTP response splitting in WEBrick (Additional fix)

There is an HTTP response splitting vulnerability in WEBrick bundled with Ruby. This vulnerability has been assigned the CVE identifier CVE-2019-16254.

Continue Reading...

CVE-2019-16255: A code injection vulnerability of Shell#[] and Shell#test

A code injection vulnerability of Shell#[] and Shell#test in a standard library (lib/shell.rb) was found. The vulnerability has been assigned the CVE identifier CVE-2019-16255.

Continue Reading...

Ruby 2.6.4 Released

Ruby 2.6.4 has been released.

Continue Reading...

Ruby 2.5.6 Released

Ruby 2.5.6 has been released.

Continue Reading...

Ruby 2.4.7 Released

Ruby 2.4.7 has been released.

Continue Reading...

Multiple jQuery vulnerabilities in RDoc

There are multiple vulnerabilities about Cross-Site Scripting (XSS) in jQuery shipped with RDoc which bundled in Ruby. All Ruby users are recommended to update Ruby to the latest release which includes the fixed version of RDoc.

Continue Reading...

Ruby 2.7.0-preview1 Released

We are pleased to announce the release of Ruby 2.7.0-preview1.

Continue Reading...

Ruby Repository Moved to Git from Subversion

Today, the canonical repository of the Ruby programming language was moved to Git from Subversion.

Continue Reading...

Ruby 2.6.3 Released

Ruby 2.6.3 has been released.

Continue Reading...

Ruby 2.4.6 Released

Ruby 2.4.6 has been released.

Continue Reading...

Support of Ruby 2.3 has ended

We announce that all support of the Ruby 2.3 series has ended.

Continue Reading...

Ruby 2.5.5 Released

Ruby 2.5.5 has been released.

Continue Reading...

Ruby 2.6.2 Released

Ruby 2.6.2 has been released.

Continue Reading...

Ruby 2.5.4 Released

Ruby 2.5.4 has been released.

Continue Reading...

Multiple vulnerabilities in RubyGems

There are multiple vulnerabilities in RubyGems bundled with Ruby. It is reported at the official blog of RubyGems.

Continue Reading...

Ruby 2.6.1 Released

Ruby 2.6.1 has been released.

Continue Reading...