Ruby 2.2 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
Ruby 2.2 reached end of life on 31 Mar 2018. It no longer receives security fixes.
Support timeline
Official dates from the Ruby release process.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 25 Dec 2014 | — |
| End of life | 31 Mar 2018 | 8.4 years ago |
| Latest release | 2.2.10 · 28 Mar 2018 | final |
The cost of staying: CVEs since end of life
37 Ruby vulnerabilities have been published since 31 Mar 2018. All were fixed in supported branches — 2.2 received none of them. Source: NVD.
Ruby CVEs published since 2.2's EOL, by year
6 of the 37 are rated critical · data refreshed 2026-08-09
Published 16 Nov 2018 · rated critical — fixed in supported branches only, never in 2.2. Details
Published 26 Nov 2019 · rated critical — fixed in supported branches only, never in 2.2. Details
Published 6 Feb 2022 · rated critical — fixed in supported branches only, never in 2.2. Details
Where to go from 2.2
Recommended target: Ruby 4.0 (supported until 31 Mar 2029).
The newest actively supported branch is Ruby 4.0 (latest release 4.0.6). Review ruby-lang.org before upgrading.
Frequently asked questions
Is Ruby 2.2 still safe to use?
No. Ruby 2.2 stopped receiving security fixes on 31 Mar 2018. Since then, 37 Ruby vulnerabilities have been published and fixed in supported branches — Ruby 2.2 received none of those fixes.
Can I still download Ruby 2.2?
Yes — the final release (2.2.10) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade Ruby 2.2 to?
Upgrade to Ruby 4.0, the newest actively supported branch (supported until 31 Mar 2029).