Hi Eliot,

Thanks for responding.  That makes total sense.  

Totally taking into account the all volunteer nature of Cygwin, would it make 
sense to defer on further non-emergency releases of Cygwin until all packages 
that are EOL have been updated?  Since this is the case with ruby, I am 
guessing it's likely the case with other packages in Cygwin too.

Is there a backlog for Cygwin somewhere, so that I can investigate this myself 
if I have time this winter?

Thank you and all the best,
Eric

-----Original Message-----
From: Eliot Moss <m...@cs.umass.edu> 
Sent: Wednesday, October 11, 2023 5:03 PM
To: Hendrickson, Eric D <e...@optum.com>; cygwin@cygwin.com
Cc: Eric @ Gmail <ericdavidhendrick...@gmail.com>
Subject: Re: Ruby EOL in Cygwin 3.4.9?

On 10/11/2023 12:37 PM, Hendrickson, Eric D via Cygwin wrote:
> Hello all,
> 
> As a ~25 year user and sometime contributor to Cygwin, I support Cygwin here 
> at my place of work.  Does anyone know why we are deploying Ruby 2.6 which 
> EOL about 18 months ago?
> 
> https://www.ruby-lang.org/en/downloads/branches/
> 
> I'm concerned about proliferation of EOL versions of Ruby in case some 
> security risk / 0Day is identified.
> 
> Please advise.
> Eric Hendrickson

If nobody has responded I can give a generic response:
"Because cygwin is all volunteer and someone has not volunteered, or did 
volunteer and is behind, or fell off the radar."

Someone else will know how to look up if there is a currently registered 
volunteer for Ruby ...

Eliot Moss

> This e-mail, including attachments, may include confidential and/or 
> proprietary information, and may be used only by the person or entity 
> to which it is addressed. If the reader of this e-mail is not the 
> intended recipient or intended recipient’s authorized agent, the 
> reader is hereby notified that any dissemination, distribution or 
> copying of this e-mail is prohibited. If you have received this e-mail 
> in error, please notify the sender by replying to this message and delete 
> this e-mail immediately.
> 

This e-mail, including attachments, may include confidential and/or
proprietary information, and may be used only by the person or entity
to which it is addressed. If the reader of this e-mail is not the intended
recipient or intended recipient’s authorized agent, the reader is hereby
notified that any dissemination, distribution or copying of this e-mail is
prohibited. If you have received this e-mail in error, please notify the
sender by replying to this message and delete this e-mail immediately.

-- 
Problem reports:      https://cygwin.com/problems.html
FAQ:                  https://cygwin.com/faq/
Documentation:        https://cygwin.com/docs.html
Unsubscribe info:     https://cygwin.com/ml/#unsubscribe-simple

Reply via email to