[#44036] [ruby-trunk - Feature #6242][Open] Ruby should support lists — "shugo (Shugo Maeda)" <redmine@...>

20 messages 2012/04/01

[#44084] [ruby-trunk - Bug #6246][Open] 1.9.3-p125 intermittent segfault — "jshow (Jodi Showers)" <jodi@...>

22 messages 2012/04/02

[#44156] [ruby-trunk - Feature #6265][Open] Remove 'useless' 'concatenation' syntax — "rosenfeld (Rodrigo Rosenfeld Rosas)" <rr.rosas@...>

45 messages 2012/04/06

[#44163] [ruby-trunk - Bug #6266][Open] encoding related exception with recent integrated psych — "jonforums (Jon Forums)" <redmine@...>

10 messages 2012/04/06

[#44303] [ruby-trunk - Feature #6284][Open] Add composition for procs — "pabloh (Pablo Herrero)" <pablodherrero@...>

57 messages 2012/04/12

[#44349] [ruby-trunk - Feature #6293][Open] new queue / blocking queues — "tenderlovemaking (Aaron Patterson)" <aaron@...>

10 messages 2012/04/13

[#44402] [ruby-trunk - Feature #6308][Open] Eliminate delegation from WeakRef — "headius (Charles Nutter)" <headius@...>

20 messages 2012/04/17

[#44403] [ruby-trunk - Feature #6309][Open] Add a reference queue for weak references — "headius (Charles Nutter)" <headius@...>

15 messages 2012/04/17

[#44533] [ruby-trunk - Bug #6341][Open] SIGSEGV: Thread.new { fork { GC.start } }.join — "rudolf (r stu3)" <redmine@...>

24 messages 2012/04/22

[#44630] [ruby-trunk - Feature #6361][Open] Bitwise string operations — "MartinBosslet (Martin Bosslet)" <Martin.Bosslet@...>

31 messages 2012/04/26

[#44648] [ruby-trunk - Feature #6367][Open] #same? for Enumerable — "prijutme4ty (Ilya Vorontsov)" <prijutme4ty@...>

16 messages 2012/04/26

[#44704] [ruby-trunk - Feature #6373][Open] public #self — "trans (Thomas Sawyer)" <transfire@...>

61 messages 2012/04/27

[#44748] [ruby-trunk - Feature #6376][Open] Feature lookup and checking if feature is loaded — "trans (Thomas Sawyer)" <transfire@...>

13 messages 2012/04/28

[ruby-core:44517] Ruby 1.9.2-p320 is released.

From: "NARUSE, Yui" <naruse@...>
Date: 2012-04-21 23:25:08 UTC
List: ruby-core #44517
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ruby 1.9.2-p320 is released.
http://www.ruby-lang.org/en/news/2012/04/21/ruby-1-9-2-p320-is-released/

This release include Security Fix for RubyGems: SSL server verification failure for remote repository.
And many bugs are fixed in this release.

== Security Fix for RubyGems: SSL server verification failure for remote repository

This release includes two security fixes in RubyGems.

 * Turn on verification of server SSL certs
 * Disallow redirects from https to http

Users who uses https source in .gemrc or /etc/gemrc are encouraged to
upgrade to 1.9.2-p320 or 1.9.3-p194.

Following is excerpted from RubyGems 1.8.23 release note [1].

"This release increases the security used when RubyGems is talking to
an https server. If you use a custom RubyGems server over SSL, this
release will cause RubyGems to no longer connect unless your SSL cert
is globally valid.

You can configure SSL certificate usage in RubyGems through the :ssl_ca_cert and :ssl_verify_mode options in ~/.gemrc and /etc/gemrc.
The recommended way is to set :ssl_ca_cert to the CA certificate for
your server or a certificate bundle containing your CA certification.

You may also set :ssl_verify_mode to 0 to completely disable SSL
certificate checks, but this is not recommended."

Credit to John Firebaugh for reporting this issue.

[1] ((<URL:https://github.com/rubygems/rubygems/blob/1.8/History.txt>))

== Fixes

* Security Fix for RubyGems: SSL server verification failure for remote repository
* other bug fixes

See ((<"tickets"|URL:https://bugs.ruby-lang.org/projects/ruby-192/issues?set_filter=1&status_id=5>)) and ((<"ChangeLog"|URL:http://svn.ruby-lang.org/repos/ruby/tags/v1_9_2_320/ChangeLog>)) for details.

== Downloads

* ((<URL:http://ftp.ruby-lang.org/pub/ruby/1.9/ruby-1.9.2-p320.tar.bz2>))
  * SIZE:   8981382 bytes
  * MD5:    b226dfe95d92750ee7163e899b33af00
  * SHA256: 6777f865cfa21ffdc167fcc4a7da05cb13aab1bd9e59bfcda82c4b32f75e6b51

* ((<URL:http://ftp.ruby-lang.org/pub/ruby/1.9/ruby-1.9.2-p320.tar.gz>))
  * SIZE:   11338691 bytes
  * MD5:    5ef5d9c07af207710bd9c2ad1cef4b42
  * SHA256: 39a1f046e8756c1885cde42b234bc608196e50feadf1d0f202f7634f4a4b1245

* ((<URL:http://ftp.ruby-lang.org/pub/ruby/1.9/ruby-1.9.2-p320.zip>))
  * SIZE:   12730896 bytes
  * MD5:    0bdfd04bfeb0933c0bdcd00e4ea94c49
  * SHA256: 83db9c86d5cf20bb91e625c3c9c1da8e61d941e1bc8ff4a1b9ea70c12f2972d3

- -- 
NARUSE, Yui  <naruse@airemix.jp>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.16 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJPk0G7AAoJELeVwgWeLAKkd9wH/0STmCSeozansx8KsqSyEFo1
f4LuwD8Yl1US7yDSZZcBOvwk9ssWdD/u//i1c+bRIZD/mL8Ru02lMJUWAf6SO5NB
EQftm18PlK7DeZLsl+zai4DHL1Z5icFICy2xS5FdX478ACA3x1/viIE5NzCUMCYO
+A4IO76owsqQF45zZvCs68Uo3/Z3kQVtSaBrvm+QcJK3Uy/nlVhLgcT4DJcQBsZl
1l2mYvOjgARuIf/i+LfelRjh89eWLBes14c298USlQqDiwmIPyu4OxfuiBmQq0K9
zIy9W1P9r00bkWDxYugLaN3tYFX0IB7R/0CBS6U6OHK4KDMY3inqZZ1sWRO3T0c=
=WkE2
-----END PGP SIGNATURE-----

In This Thread

Prev Next