Skip to content

[ruby] Update Ruby 4.0.2 → 4.0.3#1506

Open
depfu[bot] wants to merge 1 commit intomainfrom
depfu/engine/ruby-4.0.3
Open

[ruby] Update Ruby 4.0.2 → 4.0.3#1506
depfu[bot] wants to merge 1 commit intomainfrom
depfu/engine/ruby-4.0.3

Conversation

@depfu
Copy link
Copy Markdown
Contributor

@depfu depfu Bot commented Apr 29, 2026

Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.

What changed?

Release Notes

4.0.3

Posted by k0kubun on 21 Apr 2026

      <p>Ruby 4.0.3 has been released.</p>

This release only contains ERB 6.0.1.1, which fixes CVE-2026-41316.

If your application calls Marshal.load on untrusted data AND has both erb and activesupport loaded, please update your ERB to 4.0.3.1, 4.0.4.1, 6.0.1.1, 6.0.4 or later. You may use this Ruby 4.0.3 release to do so.

Release Schedule

We intend to release the latest stable Ruby version (currently Ruby 4.0) every two months following the most recent regular release. Ruby 4.0.4 will be released in May, 4.0.5 in July, 4.0.6 in September, and 4.0.7 in November.

If a change arises that significantly affects users, a release may occur earlier than planned, and the subsequent schedule may shift accordingly.


All Depfu comment commands
@​depfu refresh
Rebases against your default branch and redoes this update
@​depfu recreate
Recreates this PR, overwriting any edits that you've made to it
@​depfu merge
Merges this PR once your tests are passing and conflicts are resolved
@​depfu close
Closes this PR and deletes the branch
@​depfu reopen
Restores the branch and reopens this PR (if it's closed)
@​depfu pause
Pauses all engine updates and closes this PR

@depfu depfu Bot added the depfu label Apr 29, 2026
@depfu depfu Bot assigned mockdeep Apr 29, 2026
@depfu depfu Bot requested a review from mockdeep April 29, 2026 00:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant