CVE-2026-107715 (mechanize): Mechanize sends credential headers to another host after an HTTP redirect
In 1998 I needed to convert PDF files to text for a search engine called Alkaline, without requiring separately installed libraries. So I wrote a C++ parser. Alkaline is another story.
I recovered the source from a backup dated December 26, 1998. It reads PDF 1.0 through 1.2, follows object references and page trees, decompresses content with bundled zlib, and prints metadata, page text and bookmark titles. There are my own string, vector and hash-table libraries in there too. The encryption code is a stub. This was a work in progress.
I wasn’t reverse engineering an undocumented format. Adobe had published the specification in 1993, and my comments refer to the PDF Reference, right down…
ZJIT is now as fast as YJIT
After some infrastructure deployment shenanigans, we deployed some regions of storefront renderer (SFR) running on ZJIT. We have seen some promising numbers.
Get in losers, we’re going benchmarking
ZJIT is our new SSA-based method JIT compiler for Ruby. We’ve been working on it and blogging about it for a year and a half and recently deployed it to production.
I’m going to share some screenshots from our internal Grafana instance and use them to draw some very exciting preliminary conclusions about ZJIT.
First, ZJIT is probably as fast as or faster than YJIT. Here is a 24-hour chart of request response time comparing YJIT and ZJIT. YJIT is the green line and ZJIT is the yellow line.
…
I build a client application with an AI agent. Each piece of work, a slice, goes through the same thirteen steps. The AI does most of them. I decide at five points.
The steps
# Step Who What happens Gate / evidence
-- ---- --- ------------ ---------------
1 Request client, a wish in an e-mail, a spec chapter, or an spec and input documents in the repo
me answer to an open question
2 Evidence AI read-only probe of each external system; real response saved as a test
…Tests are code too, and they can get messy. I wanted a quick way to find the messy tests in a Ruby project, so I wrote a small gem called scrap4rb.
It copies the rules of SCRAP, a tool by Robert C. Martin (Uncle Bob) for Clojure tests. scrap4rb brings those rules to Ruby and Minitest.
What scrap4rb does with your tests:
Why bother
There are good Ruby tools that score code: flog, flay, reek and rubycritic. But they look at a test as if it were normal code, and that gives strange results:
- reek does not see a
test "..." doblock at all, because it is not a method. - rubycritic says “long is bad”. A test that is long because it checks many things gets a D.
- A test that clicks “Save”…
scrap4rb asks other questions.…
A couple of weeks ago, I gave my keynote, “The Most Valuable Engineer Isn’t Shipping Features,” at Rails World 2026 in Austin, Texas.
If you want to just go ahead and watch it, here it is.
If you’re interested in the backstory… read on.
Just a few months ago, I took myself to a somewhat secluded Airbnb near the Oregon Coast and started writing it. I ordered a stack of yellow notepads, index cards, Sharpies, and a bottle of scotch.

I had been drafting ideas before my retreat, but this was when I knew I really needed to immerse myself in the subject matter. This is what proper authors do, right?
So, I was out at the coast and found myself in a flow state, with all these wild…
A Preflight You Can Run
The SaaS Reckoning: Lessons from Guru
On October 7, I attended 1682, O3 World’s business of innovation conference at the Barnes Foundation in Philadelphia.
This year’s theme was “AI for All of Us” and one of the sessions I enjoyed the most was “The SaaS reckoning: knowledge, agents, and the future of work” by Rick Nucci, co-founder and CEO of Guru.
In this article, I’ll share Rick’s five lessons from rebuilding Guru for AI, what he thinks comes next, and where I think his points apply to companies rolling out AI today.

Accuracy, Not Access
Rick started with the question every founder asks themselves (and every good VC asks every founder):
“Why now?”
For Atlassian, the why now was the industry moving from waterfall…
Hi, Wojtek here. Let’s explore this week’s changes in the Rails codebase.
Stop setting the public-read ACL on S3 uploads for services configured with public: true
Bucket owner enforced is now both the default and the recommended S3 object ownership setting, and rejects any request that specifies an ACL. Uploading through a public: true service to such a bucket previously failed outright because Active Storage always attached a public-read ACL, with no way to opt out.
Setting this to false skips the ACL; grant public read access through a bucket policy instead. Buckets that still use ACLs can restore the previous behavior for a given service by setting the acl option explicitly in its upload…
Add maintenance_database option to the PostgreSQL adapter
Database tasks connect to the postgres database…
Rails World 2026 Recap with John Athayde
Fresh off Rails World 2026, Chris, Andrew, David, and returning guest John Athayde unpack the surprisingly emotional conversation surrounding AI, Ruby, Rails, and the future of programming. What starts as a discussion about Spinel, Roundhouse, Rust, and Rails performance quickly turns into a much bigger question: what happens to developers when writing code is no longer the main job? They dig into AI-assisted development, changing ideas around craftsmanship and creativity, the growing importance of testing and CI, and whether frameworks like Rails become more valuable in an AI-driven world. They also reflect on the mood at Rails World, autonomous cars, AI-generated design, and why the real…
Many Keepers
DHH opened Rails World by saying what he believes, plainly, and betting his company on it. That's the bar for an opening keynote. He also asked us to be optimistic, and I am, about Rails in particular. Today I open the second day of Deccan Queen on Rails, and I hope I clear the bar he set.
If you're not in the room
The talk opens by asking the room to post in the conference chat, which has been on the second screen since yesterday morning. That chat is Basecamp's Campfire, with the organizers' sign-in, branding and dashboard added in Rails, then compiled to a native binary with no Ruby in it. Everyone at the conference has been its test suite for two days.
You can't join that one, but you…
I am writing this at 5 AM, catching up on everyone’s posts from Deccan Queen on Rails, and feeling very proud of my city.
I missed the 1–4 PM talks. A true Puneri needs his afternoon sleep to toil through the night. 😂 I was also sick and medicated, which is my slightly more respectable excuse.
But seeing the day through everyone’s photos, videos, and conversations has been special. Friends from the international Rails community came to Pune, and we got to welcome them into our home culture.
That was something I really wanted this conference to do.
A Puneri welcome
The food was Puneri. The welcome was Puneri. We had modak. We had dalcha bhat. We opened the day with an all-women…
If your team uses Google Docs, Sheets, or Slides daily, you’ve probably developed a workflow that goes: open Claude, write a prompt, copy the result, switch back to the doc, paste it in, adjust the formatting, and start over.
Anthropic recently released two things in beta: Claude for Google Workspace, an add-on that puts Claude in a sidebar directly inside your files, and a set of Google Docs, Sheets, and Slides connectors that let Claude create and edit your files from the Claude interface. In this article, we’ll cover what the integration actually does, where it removes real friction, what changes when your AI setup travels with you into a document, and what to think through before…
Making a case for real macros in Ruby
#820 — October 8, 2026
Ruby Weekly
Warming Up the Puma Master Before It Forks — Using Puma with preload_app!? Your workers still start cold, each compiling templates and YJIT code on live traffic. This post covers Basecamp's fix of running real requests in the parent process before forking, giving workers a warm app.
Lewis Buckley (37signals)
🤖 Ready for AI-Native Rails Modernization? — 🚨 Rails 8.0 EOL Nov 7. Our AI agents upgrade your app on your CI runners. PRs open only when your test suite passes. You review and merge. No quiet test deletions. Join the private-beta waitlist to lock in beta…
FastRuby.io |…
RubyLLM 2.1 is out. I released it on stage at Deccan Queen on Rails in Pune.
It builds on 2.0 and adds an MCP client, typed judgments, evaluations, tool progress, OpenTelemetry tracing, and a nineteenth provider. It’s also faster, with no code changes. In this post:
- MCP client
- Judgments
- Evaluations
- Faster by default
- Tool progress
- OpenTelemetry
- Smaller changes
- Upgrading from 2.0
An MCP Client Where You Decide What the Model Sees
In RubyLLM 2.1 an MCP server is a Ruby class you own: it lives in your repo, and it says exactly which tools the model gets.
class Linear < RubyLLM::MCP
url "https://mcp.linear.app/mcp"
inputs :user
oauth owner: :user
only…A looping GIF is a practical running joke in accessibility (a11y). It moves whether you want it to or not, you can’t stop it, and screen readers have nothing to grab onto. I built a small custom element that fixes all three at once.
The whole thing is paused-gif. Drop it in your markup and it renders a still frame with a button to play the animation:
<paused-gif src="/celebration.gif" alt="A confetti cannon going off at a launch party"></paused-gif>
That’s it. Let me walk through why each accessibility decision in there matters, because that’s the interesting bit.
Pause by default
The “poster frame” (the initial image) is captured the moment the element mounts, so nothing animates until…
4.1.0.beta2 Released
RubyGems and Bundler 4.1.0.beta2 include features, enhancements, breaking changes and bug fixes.
To update to the latest RubyGems you can run:
gem update --system [--pre]
To update to the latest Bundler you can run:
gem install bundler [--pre]
bundle update --bundler=4.1.0.beta2
Release Notes
RubyGems
Changes already released in 4.0.x are not repeated here.
Features:
- Support content addressable gems in
Gem::PackageTask. Pull request #9897 by Harriet Oughton, Gira Chawda and Jenny Shen - Add
--content-addressabletogem buildand make--ruby-abionly set the Ruby ABI. Pull request #9906 by Harriet Oughton
Enhancements:
- Drop setuid, setgid and sticky bits when extracting…
I was in the audience at Rails World 2026 when Mike Dalessio, a Rails Core team member who joined earlier this year, put up a slide that said “You are not worried enough (probably).”
He had good reasons to say it.
This summer, Mike handled CVE-2026-66066, an Active Storage vulnerability that let a crafted image upload read files from the server, including your application’s secrets.
His talk, Hot Cell: Securing Active Storage in the age of AI, was half post-mortem and half proposal: if we can’t stop image libraries from being vulnerable, maybe we can stop their vulnerabilities from reaching our secrets.
In this article, you will learn what that CVE actually meant, why patching image…
Unrolled Code
The other day I was looking at a little project called grubby, a minimal static site generator for git repos, written in Ruby. The style is quite interesting. It feels solid and unapologetic:
def fill_template(template, page_title, root_prefix)
template
.gsub("{{title}}", escape_html(page_title))
.gsub("{{root}}", root_prefix)
.gsub("{{stylesheet}}") { STYLESHEET }
.gsub("{{build_date}}", BUILD_DATE)
end
Nothing is particularly optimized, it just uses available tools to do its work:
def write_page(page_path, page_title, root_prefix = "")
FileUtils.mkdir_p(File.dirname(page_path))
header = fill_template(HEADER_TEMPLATE, page_title, root_prefix)
footer = fill_temp…After running git ls-tree and collecting the filenames…

PostgreSQL does not guarantee row order without ORDER BY. Use Rails 8.2 or pg_disorder to shuffle unordered SELECT results and expose hidden order dependencies, flaky tests, and application bugs. This is chaos engineering directed at your database.
SELECT * FROM posts carries no promise about the order of the returned posts. Yet, every relational database hands them back in some order, and code and tests start depending on that order.
You can't grep for a bug like this, but you can smoke it out by deliberately shuffling the rows of every unordered…
Recorded at Rails World, Marco Roth joins the podcast to discuss the rapidly evolving future of the Rails view layer. Marco explains Herb’s integration into Rails 8.2, how its parser and tooling improve the experience of working with HTML+ERB, and how Herb creates opportunities that weren’t previously possible with traditional Rails templates.
The conversation then turns to ReactionView, Marco’s approach to bringing fine-grained reactivity to Rails applications while allowing developers to continue writing familiar ERB. Marco explains how ReactionView can identify dynamic portions of a template, track dependencies, and update the browser without requiring developers to manually…
What retry_on Actually Means
When a job fails halfway through, what runs again, and what has already happened?
Suppose a job sends a webhook. The receiving service accepts it. Then the job fails while saving the delivery receipt in your database.
You have configured retry_on for that database error. Rails schedules another attempt. When it runs, the receiving service gets the webhook again.
The retry worked as configured. The first delivery also worked.
The question I start with when reviewing a retry policy is: what could have already happened when the exception fires?
Let’s follow one job through that failure. The behavior below is checked against Rails 8.1.3.
The next attempt starts the job again
Consider this application…
Keep the Gems
GHSA-3553-vcg5-72jw (dalli): Unbounded decompression and reply sizes allow memory exhaustion
GHSA-4qp6-2jcr-596v (dalli): Routing tokens can inject meta protocol flags, and failed requests can retry forever
GHSA-m252-9cgf-vx2w (dalli): With a namespace, a retried request reads or writes a different key
GHSA-p6pm-ch9v-44vx (dalli): Pipelined get_multi can return another key's value after an error reply
GHSA-w39f-xq2m-4g8x (dalli): Forking can resend buffered memcached requests and desynchronize the parent's connection
GHSA-wr87-m4jw-29x5 (dalli): Per-request raw and the JSON serializer don't prevent unsafe deserialization
I was in the audience at Rails World 2026 when Aaron Patterson (tenderlove) kicked off the closing keynote. Aaron opened with a well-worn line: “the purpose of a system is what it does.” He wasn’t satisfied with it. The purpose of a system, he argued, is what it does for whoever is observing it.
Hand an old Nokia 3310 to someone who has never seen a cell phone before, and they might use it as a hammer. In that moment, to that person, it is a hammer. What a system does depends on who’s watching.
That distinction has a name in compiler design: The as-if rule.
In this post, we’ll walk through what the as-if rule means for Ruby’s compiler, where Ractors push it right up to its edges, and how…
Joël takes Bike Shed out onto the conference floor at RailsWorld as he interviews programer and streamer Rachael Wright-Munn, aka ChaelCodes.
Rachael talks about her efforts to index all ruby events around the world with RubyEvents.org, how she augments her workflows with years old generators rather than LLMs, the rising cost of tokens and why AI may not always be your best solution to a problem.
—
Keep up to date with all things Ruby conferences, past and future, with Rachael’s index at RubyEvents.org
Read more about the SPIDR approach Rachael mentioned.
Our guest for this episode was Rachael Wright-Munn, connect with her on LinkedIn or check out her website to follow along…
Your host for this episode has…
Gusto Went to LDX3 NYC
In September, Gusto attended LDX3 NYC — a conference entirely dedicated to leadership in tech. There were managers, directors, tech leads, and senior engineers. Attendees jumped between the technical and management stage, learning about “Re-engineering the software development playbook” on the management stage one hour and “How to kill the code review” on the technical choices stage the next.
The one thing we had in common: everyone there was invested in learning how to become a better leader.
📸 Pictured left to right: Kamilah Taylor, Vianca Martinez, Tori Huang, Rebecca Borison, Irina Khafizova, Anshuma Chandak (and Alyssa Hester here in spirit!)Because, of course, AI. Everything is changing…
Today we are releasing Hot Cell v1.0, a suite of gems that moves Active Storage’s attachment processing out of your Rails application and into an unprivileged sidecar container with no network, no credentials, and nothing on its filesystem worth stealing. Adopting it is a configuration change, not a code change. It is already running in production at 37signals, in Basecamp, HEY, and Fizzy.
I introduced Hot Cell at Rails World 2026 in a talk titled “Hot Cell: Securing Active Storage in the age of AI.” What follows is basically that talk, written down, plus a couple of things that have changed since then. (If you’d rather watch the video or flip through the slides, go for it.)
Where we are
…🎙️ Breaking Change podcast v56.0.1 - Zach Holman wants more of everything
Direct link to podcast audio file
Zach Holman, founder of Signed, joins me for another 🔥Hotfix🔥. Zach wants more of everything. Let's see what we can do about that.
Write into the show at podcast@searls.co.
Show notes:
CVE-2026-67987 (ruby_llm): Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2026-67989 (ruby_llm): Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
Continuations 2026/40: Green on JRuby
Heckuva week.
Hanami Minitest had started failing its scheduled builds due to our ongoing work on Hanami’s reloading support. I fixed it here and here. (Why do I mention such small things here in my weeknotes? Because these are just as important aspects of maintenance as everything else—fixing broken windows—and it all takes time.)
Adam merged Alexander’s transient attribute support into Rom Factory, a very handy improvement!
Adam also finished updating Rom Factory for our repo-sync, and I followed up by preparing it for automated releases. With that done, I released v0.14.0!Nice to see a few things from Sean this week. First, in Hanami Action: I reviewed and merged his fix to handle…
RubyLLM 2.0 is the biggest release since 1.0. It starts with tool approval:
class RefundOrder < RubyLLM::Tool
description "Refunds an order"
parameter :order_id, description: "ID of the order to refund"
requires_approval # that's all it takes
def execute(order_id:, tool_call: nil)
Refunds.issue(order_id:, idempotency_key: tool_call.id)
end
end
class SupportAgent < RubyLLM::Agent
chat_model Chat
tools RefundOrder
end
chat = SupportAgent.create!
chat.ask "I was charged twice for order 42." # stops before refunding
# later, when the user approves
chat = SupportAgent.find(chat.id)
chat.approve(chat.pending_approvals.first)
chat.complete # issues the refund and answers
T…
Last week the topic on everyone's mind seemed to be the future of programming. All my friends were talking about it, people I follow were talking about it, and I was thinking about it as well. Then David's (DHH's) Rails World keynote turbocharged the conversation.
His talk didn't come as a surprise to me. I was a week into rewriting HEY in Rust during Rails World. And "Pencils down" only codified how we'd been working for months at that point.
David is right. Like it or not, we programmers, like painters before us, are slowly going to disappear. AI, like the camera, completely changed the game. You can sulk about it, or you can pick up a camera, start learning, and become a photographer.
…Short URLs
Resolvers Have Types Too
In The Browser Half I looked at the part of a Hotwire app where nothing checks anything: the strings that wire Stimulus controllers to each other and to Ruby. A GraphQL server is the opposite case. Its contract is already typed and explicit, and graphql-ruby validates every incoming query against it.
What it doesn't check ahead of time is the other side: whether the Ruby behind each field returns what the field declares. A field declared null: false that comes back nil, or a field with no method behind it, is found when a request reaches it. That's the half Roundhouse can see, because it already infers the types of a Rails app's Ruby without annotations.
Following the schema down
A…
kamal-backup 1.1 adds dump, which downloads one database dump from your backups without running a restore:
bundle exec kamal-backup dump latest -o tmp/app.pgdump
It works with PostgreSQL, MySQL, MariaDB, and SQLite. Use it to look at production data locally, to give someone a dump to debug against, or to load a backup into a tool that expects a plain dump file. Before 1.1, that meant restoring somewhere first or running restic by hand inside the accessory.
How It Works
dump talks to the backup accessory over SSH, with the same user, port, proxy, and keys Kamal already uses from config/deploy.yml. The accessory reads its own mounted repository config, so your restic credentials never…
For Rails applications, you probably want to serve HTML5, and you only want to support browsers that support HTML5. And even if you must support older browsers, you probably want to make sure your application works for HTML5-compliant browsers.
If you’re using Capybara with the Selenium driver, this will happen automatically if the headless browser is HTML5-compliant. This introduces some overhead, so I try to use the Rack::Test driver if I can get away with it. Unfortunately, when using the Rack::Test driver, Capybara processes the HTML as HTML4. This can hide bugs in your HTML.
For example, when nesting button_to inside a form_for block, the form end tag emitted by button_to will close…
Generated Rails
Hifumi generates a complete Rails application from a natural-language prompt. It runs a plain rails new, then a planning model breaks your request into revisions and Claude agents write each one. The prompt steers them toward a default Rails 8 app: Tailwind and Hotwire, the default Gemfile, and sign-in via has_secure_password plus sessions rather than Devise. Each revision has to pass a verify loop before it's committed: bundle check, db:prepare, zeitwerk:check, a smoke test that requests every static GET page, and rails test. What you get at the end is an ordinary Rails repository, yours to keep.
Roundhouse reads a Rails app and compiles it, to Ruby, to native code via Spinel, and to a…
If you write software for a living, you’ve probably been told some version of this lately: the code doesn’t matter anymore. The AI writes it now. Your job is to think like a product manager, or a QA engineer, or a “maker” who describes what they want and lets the machine figure out the rest.
I don’t buy it. You’re a programmer, and that’s a great thing to be.
Things are changing radically and rapidly, but the essence of programming remains. There is still such a thing as a better architecture, a solution that better fits the problem. There is still such a thing as well-modeled and well-factored code. There is still such a thing as a great abstraction, one that gives you leverage and…
In 1997 I wrote UcsLink.Fusion for the University of Geneva. We had hundreds of PCs across the city, Sun and Windows NT servers, and Windows 95 and Linux workstations. Getting a user’s software and settings onto whichever PC they sat down at was a job for login scripts. I wrote a Delphi 2.0 application to do it instead.
UCS stood for Universal Copy System. Fusion read a script that mapped network drives, copied shared software, created shortcuts, connected printers, set environment variables and synchronized the clock. It could include other scripts, test conditions and clean up files left by a previous run. The surviving configuration maps a personal drive, a software drive and a group…
The Way and Remainder

1970 - 2024: BCC Era (Before Claude Code)
Writing software in the “before times” was an iterative process, evolving from punching holes in paper all the way to clacking away on custom, clicky mechanical keyboards.
Through variations of this process, the steps were mostly the same:
- Understand the problem
- Come up with a solution
- Break the solution into parts
- Write code that solves each part
- Test that new things work
- Test that old things still work
- Repeat as needed
As time went on, patterns emerged. Then those patterns were overused and new patterns took their place. Programming dogma went from “everything can be functional programming” to “nothing can be functional…
The Browser Half
In As If I compared two ways of making Campfire fast: compiling the Rails app with Roundhouse, and porting it by hand to Rust, as 37signals did with once-campfire-rust. Both check their output against the running Rails app. Both are, it turns out, ports of the server only.
Campfire's app/javascript is 3,749 lines. Its models are 1,375 and its controllers 1,325, so the JavaScript is larger than both together. Roundhouse copies it into the output byte for byte. The Rust port serves the Rails app's JavaScript too, and shadows exactly three files.
A bug both ports shipped
One of the Rust port's three overrides is base_autocomplete_handler.js, and its OVERRIDES.md says why: the original calls
fe…CVE-2026-12545 (hammer_cli): hammer_cli - Insecure interpolation of the $EDITOR environment variable
Direct link to podcast audio file
Matt Swanson had me back on YAGNI to talk about the fallout from DHH's Rails World keynote and what it means for your weekend. We discuss what happens to the "one-person framework" when agents write the code, how frustrating it is when something is absolutely correct but still misses the point, and how I've accidentally constructed a dark factory with agents building and maintaining my iOS apps.
We also get into what I'd tell developers who are worried about where all this is heading and why World of Warcraft is my dark horse candidate to beat Grand Theft Auto 6 in November.
Appearing on: YAGNI
Published on: 2026-10-02
Original URL: https://share.tr…
Comments? Questions? Suggestion…
Hi, it’s Greg. Let’s explore this week’s changes in the Rails codebase.
The Rails World talk recordings are online
Blazing fast, one week after the event, you can watch all the talks from Rails World on YouTube!
“Autoloading and Reloading” guide community review
The updated “Autoloading and Reloading” guide is ready for community review. Please have a loook and give feedback.
Bump minimum Ruby version to 3.3.5
This commit bumps the minimum Ruby version to 3.3.5 so the WeakKeyMap polyfill can be removed, which would allow using non-Thread/Fiber/etc. as keys, and enable a refactor to prevent iterating over every connection pool.
Look at all the things he's not doing
There’s a moment in the early seasons of South Park when Cartman et al find the source of an underwear crisis in their mountain town. It’s the underpants gnomes in their cave. They have a plan.
- Collect Underpants
- ???
- Profit
I’ve been considering David’s opening Rails World keynote and realised that this is the main problem I have with it. Rails World is about “shaping the future of Ruby on Rails”. Instead what we got was opinionmaxxing: a lot of certainty about the destination, but in his own words, not much that was ‘practical’ or ‘prescriptive’ about getting there.
- The model got good at writing code
- ???
- Models write all code, we don’t need to care
There’s a vibration…
Ruby AI News - October 2nd, 2026
Welcome to the 38th edition of Ruby AI News! This edition features… well you know what we’re talking about this edition. This is a special edition, the 39th edition will follow next week.
Here We Go
There are…
Hanami, Why?: Bits & Bobs
Welcome back to my "Hanami, Why?" series. If you missed it, be sure to read Hanami, Why?: Introductions before you start this issue. It is my intent to keep these issues focused on singular subjects whenever possible. However, in today's issue we are going to cover several topics that are too small to warrant their own issue but still important to have for context. As I mentioned, Hanami has a lot of important abstractions, and today we are going to be covering what I consider "system level" abstractions. We have lots to cover, but this context will be important for a further understanding of how Hanami works.
Dependency Injection
Most of the time Ruby is pretty great at telling you what a…
Live At Rust, Uhh, Rails World 2026
Recorded live from Rails World 2026, Andrew, Chris, David, Jason Charnes, and eventually Andy Croll, unpack the strange mood surrounding this year’s conference. Much of the conversation centers on DHH’s keynote and the increasingly agent-driven future of software development: if AI can write, debug, and even understand the code for us, what happens to the value of frameworks, developer expertise, documentation, and even Ruby itself? They also dig into Hotwire, Active Search, Herb, Active Job Continuations, security concerns around AI-generated software, and what the Ruby community might rally around if the language becomes less central to how developers identify themselves. And because it’s…
Basecamp 5 runs on Puma in cluster mode: one master process with preload_app! and 63 single-threaded workers per host, deployed as a Docker container with Kamal.
We serve Basecamp from several sites. Each site has its own web hosts and a read replica of the database, and writes go to a single primary database in one of them.
On our busiest hosts, each deploy left up to 2,000 requests waiting while the new workers warmed up. We reduced those queues by running signed-in requests through the app in the Puma master, before it forked the workers.
Why 63 single-threaded workers?
Basecamp has always served web requests from processes rather than threads. It ran on Unicorn, which only does…
NWRUG's (Manchester, UK) October 2026 meeting — It's time to bin your VCR
The next North West Ruby User Group in Manchester, UK is in a fortnight on 15 October at Colony, One Silk Street. Rob Whittaker will take us through one of his hot-takes: VCR does more damage than good, and there are imperfectly better ways to stub your external requests.
Rob Whittaker is Director of Software Development at thoughtbot. He has over two decades of professional web development experience and has worked with Ruby and Rails since 2012. (He’s also the co-organizer of NWRUG!)
We’ll be at the venue for pizza from 6:30pm with the talk starting at 7pm. Afterwards we’ll retire to The Crown & Kettle for a drink. The venue, pizza, and drinks are kindly provided by NWRUG’s sponsors Fat…
YAGNI: Camping Chair Development
I joined Matt Swanson on YAGNI to talk about how I build software now across Fireside, Flipper, and Box Out. Some of it even happens from a camping chair.
Some of the highlights:
I’m Not a Craftsman. I always thought of myself as a craftsman. Bespoke furniture. Samurai. Honor. All that. Then on December 14th I turned on a 20x Claude plan just to try Opus and realized nope, I just love shipping stuff and solving problems. These days I read the data models and the queries because those affect how fast things are for customers. JavaScript and view code? I don’t read it. Does it look right? Is it responsive? What’s my Lighthouse score? Good enough.
Stripping Back. I went through a phase of…
Garrett and I started a podcast. It’s called The Friday Deploy, and the tagline is the whole point: ship on Friday, sleep through the night.
We already do a marketing and business podcast for Fireside, so we figured, let’s go full on dev with this one. Feature flags, deployments, infrastructure, incidents, product decisions, and all the little practices that let you deploy whenever you want without the sweaty armpits. Sometimes it’ll be just me and Garrett, and sometimes we’ll bring on a guest to walk through what they do.
Subscribe on Apple Podcasts, Spotify, or RSS.
Episode 1: Changing the Wheels While the Car Is Moving
We’re almost exactly two years into owning Fireside, so for the…
Happy to report that in record time, all Rails World 2026 talks are now online.
While all four keynotes got everyone talking about AI, this year’s talks covered a good balance of what’s new in Rails and how Rails developers are using AI.
The AI-focused talks covered: making codebases agent-friendly, harness engineering, generators, AI pipelines in plain Ruby, agent loops driving Ractor-safety, building MCPs, and rapid deploys with the help of agents.
There were also talks about: Lexxy, Active Search, ONCE, Herb in Rails 8.2 and durable Active Job workflows, plus deep dives into Solid Cable, Hotwire, Kamal, sharding, the RubyGems compact index, and HotCell…
Every month, someone on our team was doing the same thing: pulling data from a handful of systems, assembling it into a document, and writing up a summary before it could go to the client. The work was not complicated. It was just slow, repetitive, and easy to get wrong.
That monthly report was not an isolated case. We’ve built a few internal tools around the same pattern: a repetitive workflow, data sitting in one or more external systems, and a human who needs to stay in the loop at the right moments. Each time we reach for a solution, we face the same question: how much infrastructure does this actually need?
In this post, we will look at the characteristics of a workflow that fit this…
Joy of the Craft
This collective was founded on a simple idea that you should enjoy the work you do including a strong sense of purpose in order to enrich the lives of your team and customers combined. Profit, while important to keep the lights on, is not the driving force. Building expertise and using software to make life more enjoyable for folks is much more rewarding. Plus, it feels good to wake up each morning knowing you are working in a code base that is well maintained, always up-to-date, a joy to use, and a benefit to society.
The Engineer’s Oath helps us never lose sight of our purpose while our Engineer’s Rigor keeps us honest because you can’t make an impact in life if…
Rails' next rich text editor hits 1.0
#819 — October 1, 2026
Ruby Weekly
Lexxy 1.0: Rails' New Rich Text Editor to Replace Trix — Built on Lexical and already powering 37signals' Basecamp 5, it gives you tables, Markdown shortcuts, smart links, syntax-highlighted code and mentions, and it's easy to swap into Action Text in place of Trix.
Jorge Manrubia (37signals)
💡 The Lexxy site has a sandbox demo if you'd like to try it out first.
Switching APM? One Ruby Gem Now Covers Distributed Tracing — Errors, N+1s, Sidekiq jobs, logs, host metrics and now distributed tracing (beta) in one Ruby gem. Every feature on every plan, unlimited…
I recently surprised someone by showing you can use any event besides the common click, submit and keydown events. The Stimulus docs list those seven default events and their shorthand equivalents. Enough for most cases. But the data-action descriptor is event->controller#method where you can bind to anything the DOM throws at you: native element events, global document events, even custom dispatched events. All work the same way.
I put together a small demo repo to show a handful of these in action. Lets go over them and maybe you find a way to refactor and simplify one of your Stimulus controllers.
First a few you probably have used before. A <textarea> fires input on every keystroke. The …

Regular SF Ruby Conference tickets are $450 through September 30. Meet Ruby friends, play The Pier, join small-group conversations, and explore the 2026 program in San Francisco.
Not a single person in the Ruby community has told us they go to conferences for anything other than meeting new people and catching up with old friends. Our community needs that shared warmth and joy more than ever.
But going to a conference alone can be intimidating. You walk into a room full of people you don't know, have no idea whom to talk to, and end up checking your phone between talks. We've all been…
I was in the audience at Rails World 2026 for Jenny Shen’s talk on the RubyGems Compact Index, the last technical talk before the closing keynote. Jenny is a Senior Developer at Shopify and a RubyGems.org maintainer, and she opened by asking the room who had heard of the compact index before. Not many hands went up, which was kind of the point: it’s a piece of infrastructure that handles tens of millions of requests a day, and most Rubyists never think about it.

Every time Bundler resolves your Gemfile, it’s talking to the compact index. In this post, we’ll walk through what the compact index actually is, how RubyGems.org keeps it in sync at scale, and two features Jenny helped ship in…
Hanami, Why?: Introductions
I mentioned in my Hello, world! post that I built this site using Hanami. This site may seem simple on the surface; it is, after all, just a blog. However, the backend is packed with features that help me day to day. I have built a tool that lets me cross-post to both Bluesky and Mastodon. I have a private journal where I can keep notes throughout the day. There is a custom analytics engine to provide me with insights on how well my blog posts are doing. There is a messaging backend that lets readers reach me through my contact form without cluttering my inbox. I have also built a task manager that syncs with both Linear and GitHub Issues and helps me track what I need to do. Most…
What does the future of Ruby and Rails look like as AI begins to fundamentally change how software gets built?
Recorded at Rails World, David sits down with longtime Rails community member Obie Fernandez to talk about the rapid rise of agentic development and what it means for programmers, teams, and the craft of software engineering. Obie argues that while AI can dramatically accelerate development, the industry is still figuring out how to apply the discipline, constraints, and guardrails necessary to use these tools effectively in production systems.
The conversation explores how software development may be moving to a new level of abstraction—away from carefully crafting…
4.0.22 Released
RubyGems 4.0.22 includes enhancements and bug fixes and Bundler 4.0.22 includes enhancements, bug fixes and documentation.
To update to the latest RubyGems you can run:
gem update --system [--pre]
To update to the latest Bundler you can run:
gem install bundler [--pre]
bundle update --bundler=4.0.22
RubyGems Release Notes
Enhancements:
- Add –source option to gem exec command. Pull request #9765 by Akshay Birajdar
- Keep credentials on redirects only within the same origin. Pull request #9909 by Hiroshi SHIBATA
- Validate the version field in Gem::Installer#verify_spec. Pull request #9890 by Hiroshi SHIBATA
- Installs bundler 4.0.22 as a default gem.
Bug fixes:
- Remove the…
Rust is the answer to the wrong question
Nokogiri, Loofah and Crass, Compiled
I watched Marco Roth’s talk at Rails World 2026, and it left me excited about where the Rails view layer is headed.
Marco has spent the last couple of years building Herb, an HTML-aware ERB parser that is on its way into Rails 8.2 core, and at Rails World he showed what he is building on top of it: A project called ReActionView.

ReActionView adds real reactivity to your existing .html.erb templates, no Hotwire, no Stimulus, no JavaScript you have to
write yourself. That is the part that got me.
Hotwire already does a lot for us, but it still asks you to write a Stimulus controller once the interaction gets specific, and Marco’s demo showed a page that updates itself because the…
Last month the Rails Foundation published something the Ruby on Rails community had not seen before: a leaderboard of coding agents scored on real Rails work. The first Agents on Rails report topped out at 92% in the Accuracy column for the best model tested, which is roughly what you would expect from a field of frontier models. The Rails API recall column tells a different story: it shows the share of runs where the model reached for the Rails API that a task was built around, instead of hand-rolling its own version. In that first report it ran from 8% to 35%, and a follow-up published on September 2 moved the top of the range to 41%.
Those results describe Writebook, the application the…
In January 1998, a classmate and I wrote a game. It was called “Bolongas zBalls”, and it was a Java applet.
You click to start, then move the mouse, without clicking. Touch the dark ball to blow it up, and the next ball turns dark. Clear them all and the next level doubles the number of balls. Touch a plain ball and it spawns another one, so if you’re sloppy, the balls multiply until you lose. Each level has a time limit.
The intro music is the theme song from Capitaine Flam, the French version of the Japanese cartoon Captain Future, which aired on TF1 in 1981. I honestly don’t remember why we used it, nor why the game is called “Bolongas”.
Applets were removed in JDK 26, which is…
In July 1998, the Internet Society held INET ‘98, “The Internet Summit”, at Palexpo in Geneva. The University of Geneva provided about 250 computers for the conference, and I was a student there. I wrote much of the conference network’s website, www.inet98.ch, and the launcher that ran on the public Windows 95 PCs instead of Explorer.

The Inet 98 Launcher was a full-height bar on the left of the screen with a button for each installed application: Internet Explorer, Netscape, PC Pine, Telnet, WS-FTP and Office 95 and 97. I wrote it in Delphi 3. It showed a screen saver when a machine sat idle, reset itself, and could reboot the PC to return it to a clean state.
It also had a…
508: The Wonders of Static Analysis
In this week’s episode of The Bike Shed, Aji and Joël dive into the distrust around the phrase ‘programmer discipline’, why you cannot just rely on willpower, and how Static Analysis tools can help with not crossing boundaries.
From competing priorities and team member changeovers to documentation not being read, things can still fall through the cracks, so having a tool that can check the ones and zeroes that you send into GitHub. So what makes Static Analysis so different to other forms of analysis? Well, you’ll have to listen to the episode to find out!
—
Mentioned in this episode:
Joel’s talk at Rails World - ‘Harness Engineering on Rails’
Justin Searle’s Standard.rb talk - …
Welcome, thoughtbot!
I’m so happy to share that thoughtbot is our newest silver sponsor!
If you’ve written Ruby for any length of time, thoughtbot has most likely helped you out. Maybe it was a blog post, an episode of The Bike Shed, one of their many open source gems, or one of the lovely humans who work there. They’ve given our community so much for so long.
Now they’re backing Hanakai too. Here’s Rob Whittaker, their director of Software Development based in the UK, on why:
thoughtbot has built web apps and open-source Ruby libraries for over 20 years. We know how much any framework depends on the people who maintain it. Ruby is stronger with a diversity of thoughts, opinions, and approaches. The…
Hardly Promethean
Last week I published What About Rails, a dive into DHH's Rails World keynote. Smarter people than me had interesting things to say about it:
You have the most powerful tool you ever had, you have become a 1000x maker, and you can't think of how to make your stack 10x better?
José Valim poses an excellent question. I tried to find an answer.
The Bottleneck Isn't Gone
They're not gonna be web apps much longer. They're gonna be native applications, because the price of developing those things has gone to damn near zero.
The move to native apps for the frontend and Rust on the backend isn't about any particular technology. It's about cost. DHH isn't the first to make this case.
Back…
I was in the audience at Rails World 2026 for Jorge Manrubia’s talk on Lexxy, a new rich text editor for Action Text. Jorge is a Principal Programmer at 37signals, and if you’ve used Active Record Encryption, you’ve used something he built.
Jorge explained why 37signals built a new editor, what Lexxy adds, and how the work opens Action Text to other editors beyond Trix, the editor that’s shipped with Action Text since day one.
In this post, we’ll walk through why Trix became a maintenance burden, why 37signals picked Meta’s Lexical framework over the more obvious open source contenders, and what Lexxy actually does differently inside Action Text.
The Problem
Trix is built on contented…
Rails at Scale, Roundhouse Performance, and AI-Era Supply Chain Security
Andrew and Chris are back with a packed episode covering everything from Rails World anticipation and Rails 8.2 to security, Ractors, AI-assisted development, and some ambitious new Ruby tooling. They dig into RubyGems recent spam-publishing incident and Trusted Publishing, look at Shopify’s push toward Ractor-safe Rails, and explore Roundhouse, a project experimenting with compiling Rails applications into entirely different target languages. They also talk about using Claude for project planning and open source maintenance, new approaches to AI beyond traditional LLMs, the surprisingly inexpensive architecture behind Turbopuffer, PlanetScale’s new TIN search extension, and Andrew’s move…
Yesterday, in Partly in the Right, I asked where the information comes from when an agent produces a result, and what checks it. Today I have a sharper version of that question, and a new piece of evidence to ask it about.
The as-if rule
Aaron Patterson's closing keynote at Rails World was about optimization, and he framed it with a rule language implementers know well. The C++ standard puts it in a footnote: an implementation "is free to disregard any requirement of this International Standard as long as the result is as if the requirement had been obeyed, as far as can be determined from the observable behavior of the program." C has the same idea without the name. The standard describes…
Before GNU Autoconf generated configure scripts, there was a DOS program called Autoconf. It let you keep one CONFIG.SYS and one AUTOEXEC.BAT, then choose among boot configurations by pressing a key.
You did not have to wait for a menu. The PC BIOS kept early keystrokes in its keyboard queue, so you could press a configuration letter before AUTOCONF.SYS had even loaded. When the driver finally ran, it found the key and continued immediately.
I did not write the original. I copied its x86 assembly source by hand from a French computer magazine. It was the first assembly program I had ever seen and the first piece of code I compiled. I spent the next three or four years extending it into my…
This was a good week for progress on our code!
A couple of tests started flaking on JRuby mid-week. I like to get on top of these pretty quickly, so I pushed up fixes to dry-monads and dry-effects. Now that we’ve achived full JRuby support across Dry, I’m very serious about making sure we keep it!
Adam has been on a tear lately. This week he added
%formatting support to the newDry::CLI::Style::Text, and prepared a built-in spinner for Dry CLI!I merged a fix to make provider usage work inside Hanami slice class bodies, and thereby restored single-file Hanami apps. Now we have a test for it, which will help ensure we don’t accidentally lose the capability again.
A few weeks ago Aaron…
Also merged a nice little bug fix from Aaron about routes helpers finding the correct URLs for routes mounted in slices.
(Have you checked out Aaron’s shiny new homepage, by the way? It’s made in Hanami!).My…
Lexxy 1.0 is here
Today we are releasing the version 1.0 of Lexxy. Lexxy is a rich text editor for Rails built on Lexical. It already powers Basecamp, Fizzy and many others, and it will become the default editor in Rails. I recently presented it in Rails World (slides, video coming soon). This is the article version of my talk.
Trix hit a wall
Trix has been our editor since 2015, and every Rails app’s editor since Action Text shipped in Rails 6. It’s small and reliable, and it has served millions of people for a decade. But in the last few years our customers kept asking for features like tables or code highlighting, and we kept struggling to deliver them. The reason is the Trix document model.
A Trix…
Partly in the Right
On Kids and Football
My father was born and raised in a village called Moldovița, nestled at the feet of the densely forested Carpathian mountains in Romania. One of my favorite tales he used to tell us about his childhood is about the Jewish kids’ football team Maccabi Moldovița. All of the boys dreamed about playing in a football team, but they didn’t even have a real ball. This didn’t stop them though, and they came up with a plan: the Schmoll shoe paste company had a sales promotion: collect 100 shoe paste caps, send them to the factory, and you’ll get a free football! The kids did their best to waste as much shoe paste as they could, which of course led to the indignation of their parents, but finally…
Hello, world!
Hello, and welcome to my new website! My name is Aaron and I have been writing software since I was thirteen years old (twenty-seven years ago). I am a senior software engineer at Credit Ninja and have worked for companies like Root Insurance and Zillow. The main focus throughout my career has been backend web development using my primary love language, Ruby. In my spare time, I contribute to the Hanakai organization, working on Hanami, dry-rb, and ROM. Over the last few years, I have also begun to fall in love with Rust and have published a handful of projects. I am from and live in San Antonio, Texas. I have four kids ranging in age from seven to twenty-two.
This will be the fourth(?)…
Hello! Recently I needed bike lights for my bike. And I remembered that I already had rechargeable bike lights that I bought ten years ago, that I hadn’t tried in a long time. I tried to recharge them, but after fully charging them, they only worked for maybe 5 minutes before they turned off again.
I don’t know much about electronics, but I’ve been curious about whether it’s possible to fix old electronics for a long time, and this seemed like the perfect repair project because I might just need to replace the battery.
So I went to the local queer makerspace where I’m a member to use the soldering iron and try to do it! I don’t know much about electronics and this post does not contain any…
6 levels of knowledge management maturity in organizations
“Zapomniałem” is Polish for “I forgot”.
On Arkency’s Slack, our main communication channel, it has been used over 1200 times.
And I truly believe I work with exceptionally organized and meticulous people.
That only confirms what I wrote in my previous post: organizations are surprisingly good at forgetting.
That post described how we maintain an organizational knowledge graph with an LLM and event sourcing.
It was about the destination.
This one is about the road that led us there.
Looking back at how we handle knowledge at Arkency, I identified 6 levels of maturity.
I presented them yesterday at Programistok in Białystok,…
GHSA-6wmv-xq9m-fmp7 (dalli): Memcached command injection through numeric arguments to incr/decr and fetch_with_lock
GHSA-42qh-8mx8-7wqm (rack-proxy): HTTP response smuggling via ambiguous backend response framing in rack-proxy 1.x
The Job Was Enqueued by Older Code
What happens to the jobs already in the queue when I rename their class?
The code change looks straightforward: rename the file, update the callers, and fix the tests.
But a job enqueued before the deploy might wait hours or days before a worker picks it up. By then, the old class is gone.
I wanted to follow that job through the rename and work out what the new release still needs to support. Keeping the old class around seems reasonable, but then we need to decide when we can remove it.
Let’s start by removing it.
Suppose we rename FulfillOrderJob to DispatchOrderJob, update every call site, and deploy. New requests now enqueue DispatchOrderJob. A job scheduled by the previous release still…
Introducing Asgard: a Thor-based task runner where tasks live in .loki files
Asgard 0.4.0 was released on September 26, 2026. It is a Ruby task runner: define tasks as methods in a .loki file, declare what each task depends on, and run them with asgard <task>. The command line is handled by Thor, so subcommands, typed options, argument validation, and generated help are all available without extra code.
The part I’d point to first is how dependencies are declared. One depends_on line says which prerequisites run one after another, which run at the same time, and in what order those groups happen. Serial, concurrent, or a mix of both, all in the same line, with no separate job-count flag…
Pencils Down: My Take on DHH’s Rails World 2026 Keynote
This week David Heinemeier Hansson opened Rails World 2026 in Austin, Texas, with a keynote that has had the Ruby community talking ever since. A few days later Matt Solt asked me, “By the way, I’m curious to know your thoughts on David’s keynote.”
I watched it. I agree with him 100%.
My reply to Matt ran longer than he probably expected, and it turned into this post.
What David said
If you haven’t seen it, the opening keynote is on YouTube. The short version: hand-writing code is no longer an economically viable skill for most programmers at most companies. He didn’t pitch that as doom. He pitched it as an inflection point.
He…



