From: snacktime Date: 2006-08-11T02:39:25+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) The only issue I have is with not disclosing the nature of the problem. Upgrading without testing just isn't an option where I work. If an application has to come down for adequate testing, that's how it's done. We freeze the releases we run to the application, and in some cases have applied patches against the source. Depending on the nature of the problem, we could leave the applications up while we test the new version of rails, or take them down if that was necessary. However in a case like this we are flying blind. Not disclosing the nature of the problem and it's potential impact is simply the wrong approach. I'm sure the core team made the decision they thought was best, it just happened to be the wrong decision. Chris