「每次提起升版就被已讀。」
WebConf 2025 Huli 的演講重燃大家對 ReDoS 的關注,那 Ruby 圈是如何應對此安全性議題呢?
2022 年底,Ruby 3.2 大幅改善了 Regexp 的安全性與效能;隨著 Ruby 4 發佈、Ruby 3.2 即將進入 EOL,來談談 #17837 與 #19104 的設計與權衡,以及為何在 2026 更應重視 ReDoS 議題。
• RubyJam 2026.03 活動頁面: https://rubytaiwan.kktix.cc/events/rubyjam2603
• Ruby Taiwan 更多社群資訊 : https://linktr.ee/rubytaiwan2008
"Left on read... every time I suggest a version upgrade."
The talk by Huli at WebConf 2025 reignited the community's focus on ReDoS (Regular Expression Denial of Service). But how exactly is the Ruby world tackling this security challenge?
In late 2022, Ruby 3.2 introduced significant improvements to Regexp security and performance. With Ruby 4 recently released and Ruby 3.2 approaching its EOL, let’s discuss the design and trade-offs behind Feature #17837 and #19104, and why we should pay attention to ReDoS more than ever in 2026.
• RubyJam 2026.03 Event Page: https://rubytaiwan.kktix.cc/events/rubyjam2603
• RubyTaiwan All links: https://linktr.ee/rubytaiwan2008