Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

downgrade required ruby version to 2.6.6 for smart alerts #10

Closed
wants to merge 1 commit into from
Closed

downgrade required ruby version to 2.6.6 for smart alerts #10

wants to merge 1 commit into from

Conversation

GregRockPS
Copy link

No description provided.

@GregRockPS GregRockPS closed this Oct 18, 2023
@sferik
Copy link
Owner

sferik commented Oct 18, 2023

Hi Greg,

Ruby 2.6 is past its end of life and is now unsupported, meaning it has not received bug fixes or critical security updates since April 12, 2022.

Specifically, Ruby 2.6.6 has known security bugs that were patched in 2.6.7, 2.6.8, 2.6.9, and 2.6.10:

Running Ruby 2.6.6 in production means you are unnecessarily exposing yourself (and your customers) to these vulnerabilities and others that have been discovered since Ruby 2.6 fell out of maintenance.

I strongly advise that you upgrade to Ruby 3 immediately—ideally version 3.2 or 3.1, since 3.0 will stop receiving critical security updates on March 31, 2024—instead of modifying this gem to work with Ruby 2.6.6.


I noticed you are a Staff Software Engineer at ParentSquare. I actually use ParentSquare on a daily basis to send and receive private communications to and from my children’s preschool. I would be very disappointed to learn that ParentSquare is running a known vulnerable Ruby version in production, given the sensitive data stored and transmitted by your company.

I would also kindly request that if ParentSquare is using this gem, they consider sponsoring my work on it. For as little as $1/month, the ParentSquare logo could appear here and I would prioritize your bug reports and feature requests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants