[Rails] What is Rails fixing versions in Gemfile?

2013-02-16 Thread Slava Vishnyakov
Hello, I'd like to ask why is Rails fixing it's version, like gem 'rails', '3.2.12' ? Given the recent attacks on Rails - wouldn't it be more secure to not fix the version? Maybe have something like '~3.2.12' ? -- You received this message because you are subscribed to the Google Groups

Re: [Rails] What is Rails fixing versions in Gemfile?

2013-02-16 Thread Jordon Bedwell
On 02/16/2013 07:07 AM, Slava Vishnyakov wrote: I'd like to ask why is Rails fixing it's version, like gem 'rails', '3.2.12' ? Given the recent attacks on Rails - wouldn't it be more secure to not fix the version? Maybe have something like '~3.2.12' ? While I agree, I don't see a valid