Ruby 2.5.3/2.4.5/2.3.8 packages to address CVEs

140 views
Skip to first unread message

pe...@valimail.com

unread,
Oct 21, 2018, 10:41:05 PM10/21/18
to Brightbox Ruby Ubuntu Packaging
There were a number of security releases for Ruby last week - 2.5.3, 2.4.5, 2.3.8.

These address the following CVEs:

Do you know when there will be updated Brightbox packages for these Ruby versions?  Especially 2.5.3?

Thanks.

Best,

Peter

John Leach

unread,
Oct 24, 2018, 7:29:41 AM10/24/18
to brightbox-ruby-...@googlegroups.com
Packages for 2.5.3, 2.4.5 and 2.3.8 are now available in ruby-ng-
experimental. They've passed all our local install tests and we'll be
copying them over to ruby-ng soon, but any other testing feedback in
the mean time is appreciated.

Also, I fixed the bionic builds, so they're available for testing too.
I've more thorough testing to do with them though, as there was some
previous issues with the newer gcc in bionic. Again, any feedback would
be great. Run your test suites with it :)

Backports to <= 2.2 in progress.

John.
--
https://www.brightbox.com

On Sun, 2018-10-21 at 19:41 -0700, peter via Brightbox Ruby Ubuntu

bra...@volunteerhq.org

unread,
Nov 8, 2018, 3:28:22 PM11/8/18
to Brightbox Ruby Ubuntu Packaging
Hi John,

Any update on when these versions will be available?

Thanks,
Brandon

barn...@gmail.com

unread,
Nov 12, 2018, 8:50:39 AM11/12/18
to Brightbox Ruby Ubuntu Packaging
On Wednesday, 24 October 2018 12:29:41 UTC+1, John Leach wrote:
> Packages for 2.5.3, 2.4.5 and 2.3.8 are now available in ruby-ng-
> experimental. They've passed all our local install tests and we'll be
> copying them over to ruby-ng soon, but any other testing feedback in
> the mean time is appreciated.

Hi, do you have an idea when these will make it to ruby-ng?

Thanks very much for maintaining the repo!

Barnaby

min...@gmail.com

unread,
Nov 12, 2018, 8:50:39 AM11/12/18
to Brightbox Ruby Ubuntu Packaging
Is there an ETA on when the 2.5.3 packages will make it into the non-experimental PPA?

sacro...@gmail.com

unread,
Nov 12, 2018, 8:50:39 AM11/12/18
to Brightbox Ruby Ubuntu Packaging
Hi John,

any ETA on when packages will be copied to ruby-ng?

Thanks,
Cristian

John Leach

unread,
Nov 12, 2018, 8:56:45 AM11/12/18
to brightbox-ruby-...@googlegroups.com
Hi all,

All these are now copied over to ruby-ng, Bionic included.

<= 2.2 still in progress.

John.
Reply all
Reply to author
Forward
0 new messages