Skip to content
GitLab
Next
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 44,761
    • Issues 44,761
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 1,330
    • Merge requests 1,330
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.orgGitLab.org
  • GitLabGitLab
  • Issues
  • #335890
Closed
Open
Issue created Jul 12, 2021 by Steve Terhar@SteveTerharDeveloper11 of 12 checklist items completed11/12 checklist items

Upgrade to ruby 2.7.4

Ruby 2.7.4 has been released.
https://www.ruby-lang.org/en/news/2021/07/07/ruby-2-7-4-released/

This includes security updates for issues that have been causing Critical / High findings in customer scans of Gitlab.

We should consider updating to this most recent patch.

Link to most recent ruby update:

  • &2380 (closed)

Required MRs

  • gitlab-rails: !68363 (merged)
  • gitaly-ruby: gitaly!3771 (merged)
  • build images: gitlab-build-images!428 (merged)
  • CNG: gitlab-org/build/CNG!739 (merged)
  • omnibus: omnibus-gitlab!5545 (merged)
  • gitlab chart: gitlab-org/charts/gitlab!2162 (merged)
  • GDK: gitlab-development-kit!2137 (merged)
  • GCK: gitlab-compose-kit!176 (merged)
  • labkit: labkit-ruby!79
  • gitlab-exporter: gitlab-exporter!150 (merged)
  • gitlab-experiment: https://gitlab.com/gitlab-org/gitlab-experiment/-/merge_requests/128
  • gollum: I don't think it's needed, since it has no .ruby-version and asks for 2.7 in CI

Release notes

The version of Ruby used by GitLab has been updated to 2.7.4 in order to mitigate security concerns.

Edited Sep 13, 2021 by Changzheng Liu
Assignee
Assign to
Time tracking