From: David Heinemeier Hansson Date: 2006-08-10T04:55:07+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) > There are competing interests at stake beyond adhering to general > open-source philosophy. If, for example, a vulnerability is very > easily exploited, and could cause data loss or other significant > damage, there's a very strong case to be made for fixing first and > giving explicit documentation later. > > In other words, if you lose your entire database two hours after the > announcement (because it was announced at 2am local time, say), it's > pretty cold comfort that the vulnerability was openly discussed and > evaluated according to all the best practices of the open-source > community. What Matthew said. We'll release the details once everyone has had a fair chance to upgrade. BTW, there was a problem with the gem of Action Pack which caused issue when trying to install on Windows (RubyGems recorded the wrong size for the gem). We've replaced the gem with one of proper meta data, so you should be good to go on redownloading shortly. -- David Heinemeier Hansson http://www.loudthinking.com -- Broadcasting Brain http://www.basecamphq.com -- Online project management http://www.backpackit.com -- Personal information manager http://www.rubyonrails.com -- Web-application framework