Product overview
Redmine is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Networked or application service delivery
- Administrative and operational interfaces
- Versioned maintenance and security updates
Typical use
Used to provide application, infrastructure or operational services to other systems and users.
Deployment
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | Redmine |
|---|
| Release | Lifecycle policy |
|---|
| Start or release | Not extracted |
|---|
| Lifecycle boundary | Continuous or not dated in the source |
|---|
| Date precision | Unknown |
|---|
Known exploited vulnerabilities
Catalogue updated 1 Oct 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
No CISA known-exploited entries currently match this mapped product family.
This does not mean the product has no vulnerabilities.
Package vulnerability advisories
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Source evidence
PRIMARYManual
Redmine official lifecycle source
Redmine has been migrated to Rails 8 ( #43205 ). | Ruby 4.0 is now supported ( #43650 ). Note: Ruby versions 4.0.0 to 4.0.3 have a significant wiki rendering slowdown caused by a regression in the Ruby runtime itself ( #43737 , tracked upstream at bugs.ruby-lang.org #21856 ). This was fixed upstream in Ruby 4.0.4, so we recommend running Redmine 7.0 on Ruby 4.0.4 or later. | Several core dependencies have been updated, including Propshaft, Commonmarker, Rubyzip, Trilogy, Rouge, the pg and sqlite3 gems, and others. | The Raphael.js dependency has been removed in favor of native SVG APIs ( #43845 ). | ChartJs has been upgraded and migrated to ES Modules ( #44018 ). | html-pipeline gem has been removed. Loofah is used now for HTML filtering, and Textile processing has been aligned with the same approach used for CommonMark ( #42737 , #43643 ). Some existing code related to text formatting have been moved to scrubbers ( #43745 ). | Deprecated icon-* CSS classes, kept temporarily since 6.0 for backward compatibility, have now been removed from core stylesheets and moved to `legacy-icons-compat.css`, completing the transition to Tabler SVG icons ( #43206 ). The legacy CSS file still can be imported by theme or plugin developers using the standard import syntax.
Publisher identity used by product-specific official-source collectors.
First collected 12 Sep 2026 · Last collected 25 Sep 2026 · Review state accepted
Open official vendor source ↗