ruby-advisory-db icon indicating copy to clipboard operation
ruby-advisory-db copied to clipboard

Include warnings for EOL ruby and gems

Open cyc115 opened this issue 5 years ago • 4 comments

End of life Ruby and Gems could be something ruby-advisory-db tracks. Tools like bundler-audit could then use this information to alert users fail builds. Any thoughts?

cyc115 avatar Sep 27 '19 04:09 cyc115

I like the idea. Thoughts on how we might show this to folks? Or the schema format?

reedloden avatar Sep 30 '19 07:09 reedloden

I like the idea, though can I ask it be the default but disable-able behind a flag. Since this forms part of CI for a lot of places this could end up blocking a lot of builds. Thoughts go out to a team I know contractually obligated to stay on ruby 1.8.x.

BookOfGreg avatar Sep 30 '19 07:09 BookOfGreg

I like the idea, though can I ask it be the default but disable-able behind a flag. Since this forms part of CI for a lot of places this could end up blocking a lot of builds. Thoughts go out to a team I know contractually obligated to stay on ruby 1.8.x.

Good idea, I like the idea of switching on with a flag (vs. on by default and switch off with flag). I think opting in to EoL check is better than opting out because this could unnecessarily block builds.

Thoughts on how we might show this to folks? Or the schema format?

😄 Haven't had much thought on this yet. But will do this weekend.

UPDATE: I've opened https://github.com/rubysec/bundler-audit/issues/227 for discussion.

cyc115 avatar Oct 02 '19 19:10 cyc115

End-of-Lifed rubies could be stored in ruby-versions. End-of-Lifing isn't really a Security Advisory, so I don't think it really fits here. Although, Advisories for vulnerabilities in EOLed Rubies definitely can be added to ruby-advisory-db.

postmodern avatar Oct 24 '19 02:10 postmodern

Closing this as the scope of ruby-advisory-db is security advisories for vulnerabilities.

postmodern avatar May 23 '23 19:05 postmodern

Might be of interest: https://github.com/marketplace/actions/xeol-end-of-life-eol-scan

jasnow avatar Jul 14 '23 14:07 jasnow