[ruby-core:66271] Re: Remove REXML instead of patching it

From: Zachary Scott <e@...>
Date: 2014-11-13 22:21:34 UTC
List: ruby-core #66271
Could you open a feature request on bugs.ruby-lang.org please?

Maybe there's al ready an existing ticket..

On Thu, Nov 13, 2014 at 10:34 AM, Michael Grosser <michael@grosser.it> wrote:
> There have been at least 3 rexml vulerabilities to date,
> having to patch ruby just to make sure it's not being used is taking a lot
> of time/effort.
>
> Afaik most people do not use xml anyway (and especially not rexml), just for
> comparison: it would make much more sense to have json included, but it's
> not.
>
> So let's just drop it & make it a gem.

In This Thread

Prev Next