Recent News

Ruby 3.3.1 Released

Ruby 3.3.1 has been released.

Continue Reading...

Ruby 3.2.4 Released

Ruby 3.2.4 has been released.

Continue Reading...

Ruby 3.1.5 Released

Ruby 3.1.5 has been released.

Continue Reading...

Ruby 3.0.7 Released

Ruby 3.0.7 has been released.

Continue Reading...

CVE-2024-27282: Arbitrary memory address read vulnerability with Regex search

We have released the Ruby version 3.0.7, 3.1.5, 3.2.4 and 3.3.1 that have a security fix for an arbitrary memory address read vulnerability in Regex search. This vulnerability has been assigned the CVE identifier CVE-2024-27282.

Continue Reading...

CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc

We have released the RDoc gem version 6.3.4.1, 6.4.1.1, 6.5.1.1 and 6.6.3.1 that have a security fix for a RCE vulnerability. This vulnerability has been assigned the CVE identifier CVE-2024-27281.

Continue Reading...

CVE-2024-27280: Buffer overread vulnerability in StringIO

We have released the StringIO gem version 3.0.1.1 and 3.0.1.2 that have a security fix for a buffer overread vulnerability. This vulnerability has been assigned the CVE identifier CVE-2024-27280.

Continue Reading...

Ruby 3.2.3 Released

Ruby 3.2.3 has been released.

Continue Reading...

Ruby 3.3.0 Released

We are pleased to announce the release of Ruby 3.3.0. Ruby 3.3 adds a new parser named Prism, uses Lrama as a parser generator, adds a new pure-Ruby JIT compiler named RJIT, and many performance improvements especially YJIT.

Continue Reading...

Ruby 3.3.0-rc1 Released

We are pleased to announce the release of Ruby 3.3.0-rc1. Ruby 3.3 adds a new parser named Prism, uses Lrama as a parser generator, adds a new pure-Ruby JIT compiler named RJIT, and many performance improvements especially YJIT.

Continue Reading...