Rails version 3.2.7 has been released(weblog.rubyonrails.org) |
Rails version 3.2.7 has been released(weblog.rubyonrails.org) |
If you have questions about the release, or the security issue, fire away. :-)
People tend to talk about what's new and shiny because there is greater social reward for being the advocate of something new/better than there is to say "what we have is good enough and so I like using it!"
I think asking about alternatives is fair game.
You know where the "better alternatives to Rails" thread goes, and it's nowhere helpful for a security advisory post. But, your call, not mine.
MRI scares the bejeezus out of me.
JRuby also suffers from the global symbol table =( so it does not avoid the potential denial attack through symbolizing..