Re: [go-cd] Ruby on Rails-Server-Version end-of-life

2023-11-22 Thread Erik Wölfel
Hey Chad, thanks for the answer. Unfortunately we are no ruby experts at all. The SpringSec-Issues are news to us, we could support with those. Team Hopper OTTO Chad Wilson schrieb am Mittwoch, 22. November 2023 um 08:20:06 UTC+1: > Hiya Erik > > Plans, yes:

Re: [go-cd] Ruby on Rails-Server-Version end-of-life

2023-11-21 Thread Chad Wilson
Hiya Erik Plans, yes: https://github.com/gocd/gocd/pull/12077 - but it's not EOL *quite* yet :P. Arguably there are riskier pieces of EOL software within GoCD than Rails right now (Spring Security, Spring Framework) and if things get messy I'm more inclined to focus on pieces with better

[go-cd] Ruby on Rails-Server-Version end-of-life

2023-11-21 Thread Erik Wölfel
Dear Gocd-People, first of all we love gocd and admire your work :-) Our security system mentions gocd using end-of-life software having the ruby on rails-server on version 6.1.7.6 which will be out of security support in half a year (1st June 24, https://endoflife.date/rails) Are there any