Skip to content

[Security] Upgrade Ruby 3.1.1 → 3.3.10 (Critical EOL remediation) - #31

Open
sbalogun-kroo wants to merge 1 commit into
mainfrom
sec/upgrade-ruby-3.3.10
Open

[Security] Upgrade Ruby 3.1.1 → 3.3.10 (Critical EOL remediation)#31
sbalogun-kroo wants to merge 1 commit into
mainfrom
sec/upgrade-ruby-3.3.10

Conversation

@sbalogun-kroo

Copy link
Copy Markdown

Summary

Upgrade Ruby from 3.1.1 to 3.3.10 to remediate the critical Aikido finding: Ruby version no longer receiving security updates (score 99, Out of SLA).

Changes

File Change
.ruby-version Ruby 3.1.1 → 3.3.10

Context

Ruby is used for InSpec compliance tests in this terraform module. This is a low-risk change — just bumping the version file for the test tooling runtime.

Validation needed

  • CI pipeline passes
  • InSpec tests still execute correctly

- Ruby 3.1.1 is End-of-Life and no longer receives security patches
- Upgrade to Ruby 3.3.10 (latest 3.3.x LTS patch)
- Resolves critical Aikido finding: Ruby version no longer receiving security updates
- Ruby is used for InSpec compliance tests in this terraform module
@sbalogun-kroo sbalogun-kroo added the Kroo Label created by Aikido AutoFix label Jun 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Kroo Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant