Rubyland

news, opinion, tutorials, about ruby, aggregated
Sources About
RubyGems Blog 

4.0.18 Released

The Rails Tech Debt Blog 

Why Patching the Gem Didn’t Fix CVE-2026-66066

Ruby Central 

Ruby Runway Spotlight: Joe Masilotti of Ruby Native

Evil Martians 

+14% activated users for AppSignal: designing a new homepage in code

The Rails Tech Debt Blog 

Running a Ruby MCP Server in Production

All about coding 

Tell the Agent to Write Its Scripts in Ruby

OmbuLabs.ai 

EU AI Act Article 50: The SMB Checklist

Josh Software 

Why HTTP Introduced the QUERY Method: Solving the Limitations of GET and POST

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

RSpec Expectations: You’re Probably Using the Wrong Matcher

Island94.org 

How to programmatically upload attachments to GitHub Issues, Pull Requests, and Comments, finally, for now

Gusto Engineering - Medium 

Eval-Driven Design Systems (Part 2)

Tim Riley 

Continuations 2026/31: Repeatable options

RailsCarma – Ruby on Rails Development Company specializing in Offshore Development 

How Startups Can Build AI Products Faster with Ruby on Rails

Posts on Kevin Murphy 

Frequently Played August 2026

Drifting Ruby Screencasts 

Function Calling

Rails Revelry 

What Happens When You Call save

Code Otaku 

The Case of the Readable Dead Connection: A Ruby Mystery

Alchemists: Articles 

Big Sky Dev Con 2026

Ruby on Rails: Compress the complexity of modern web apps 

Faster i18n loading, thread-safe routes, and more!

Code Otaku 

Making Failure More Predictable in Ruby Systems

Island94.org 

Running code when the Ruby on Rails webserver boots

RubySec 

CVE-2026-54659 (pagy): Pagy I18n locale option is not validated before being used in a file path

RubySec 

GHSA-pmwx-rm49-xv39 (activerecord-tenanted): ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

RubySec 

GHSA-r827-6rm4-59pg (alchemy_cms): Stored XSS via unsanitized SVG attachment replacement

Remote Ruby 

Big Wins For RubyConf and Grandma

RailsCarma – Ruby on Rails Development Company specializing in Offshore Development 

Ruby on Rails for Enterprise Automation Solutions: Transforming Modern Business Operations

André Arko 

Ruby Central's Destructive Legacy

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Understanding the Rails Middleware Stack

Awesome Ruby Newsletter 

💎 Issue 532 - It doesn’t matter whether “Matz is nice”

The Rails Tech Debt Blog 

Migrating from sass-rails to Dart Sass

OmbuLabs.ai 

AI Assistant for Our Blog Writing Process

Ruby Central 

Ruby Runway Spotlight: Michael Carroll of Coolhand Labs

Ruby Weekly 

You need to upgrade Rails 7.x and 8.x now

Rails Designer Blog 

Courrier: a gem to send emails without SMTP

RubySec 

CVE-2026-66066 (activestorage): Possible arbitrary file read and remote code execution in Active Storage variant processing

RubySec 

GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability

Ruby on Rails: Compress the complexity of modern web apps 

Rails Versions 7.2.3.2, 8.0.5.1, and 8.1.3.1 have been released!

Ruby on Rails: Compress the complexity of modern web apps 

Nominations open for the 2026 Rails Luminary Awards

The Ruby on Rails Podcast 

Episode 545: Post RubyConf conversation with Neha Abraham

Syed Aslam 

Why Active Record's Snapshot Semantics Are a Trade-off, Not a Missing Feature

Evil Martians 

The secure way to release an npm package in 2026

Rails at Scale 

The inliner is yielding benefits for ZJIT

OmbuLabs.ai 

Turning User Ideas into AI-Generated Designs

The Rails Tech Debt Blog 

Tracking LLM Latency & Cost with Rails Events

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Ruby Association Activity Report 2026: Matz, Fastly, and Ruby Grant Projects Take the Stage

Gusto Engineering - Medium 

Eval-Driven Design Systems (Part 1)

Ruby Central 

Scholars & Guides Spotlight: Madeline Caples on Learning to Code Alongside AI

Tim Riley 

Continuations 2026/30: Big triage

Ruby Magic by AppSignal 

Why Your Sidekiq Jobs Are Slower Than You Think, and How AppSignal Fixes That

Rails Blocks - Component Updates 

Theme Builder and Semantic Component Themes

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Rails Isn’t Getting Bigger It’s Getting Sharper

byroot’s blog 

Optimizing Ruby’s JSON, Part 8

Rails Revelry 

How Rails knows what changed

RubySec 

GHSA-r766-3v88-pfcf (where_is_waldo): where_is_waldo authenticates ActionCable connections from a client-supplied subject_id when no authenticate_proc is configured

tekin.co.uk 

Overriding Rails’ default validation error message format

tekin.co.uk 

10 Things You Might Not Know About Rails i18n

Julik Tarkhanov 

Have less stuff

Ruby on Rails: Compress the complexity of modern web apps 

Happy Anniversary Rails!

SINAPTIA 

Ruby Argentina July meetup

Ruby on Rails: Compress the complexity of modern web apps 

New Rails reference app library published

avdi.codes 

https://avdi.codes/175297-2/?utm_source=rss&utm_medium=rss&utm_campaign=175297-2

Remote Ruby 

A Deep Dive into GitHub Actions

Awesome Ruby Newsletter 

💎 Issue 531 - RubyGems.org security advisory: Possible leak of legacy API keys via improper cache configuration

Saeloun Blog 

Rails 8 Introduces Kamal 2 For Zero Downtime Deployments

The Rails Tech Debt Blog 

Rake Beyond Rails: A Build Tool You Know

Ruby Weekly 

Why RubyGems just revoked every legacy API key

Rails Designer Blog 

Recreating Stimulus: how data-controller works under the hood

Syed Aslam 

Git Worktrees: Multiple Branches Without the Checkout Shuffle

justin․searls․co - Digest 

🎙️ Breaking Change podcast v54 - Hot Sleeper

RubyGems Blog 

Security advisory: Possible leak of legacy API keys via improper cache configuration

JRuby.org News 

JRuby 10.1.1.0 Released

SINAPTIA 

Using OpenSpec in Rails applications

The Ruby on Rails Podcast 

Episode 544: RubyConf 2026 Hallway Track

RubyGems Blog 

4.0.17 Released

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Ruby May Finally Fix the Famous “Norway Problem”

RubySec 

GHSA-7m8w-vg9p-qjr6 (alchemy_cms): Stored XSS in SelectView via Missing Server-Side Option Validation

RubySec 

GHSA-pm72-wq9v-wvfh (alchemy_cms): Stored XSS in PictureView figcaption via html_safe on User Caption

Julia Evans 

Some more things about Django I've been enjoying

RubyMine : Intelligent Ruby and Rails IDE | The JetBrains Blog 

RubyMine 2026.2: Agentic Debugging, Native GitHub Copilot Integration, Default Symbol-Based Code Insight, and More

RailsCarma – Ruby on Rails Development Company specializing in Offshore Development 

Workflow Automation with Ruby on Rails: A Practical Guide

Ruby Central 

Ruby Runway Spotlight: Paresh Sharma of Viveture

The Rails Tech Debt Blog 

Automate Tech Debt Audits with Claude Code

Evil Martians 

Which AI actually reads your site? Two months of LLM traffic, measured

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Beyond tenant_id: Treating Multi-Tenancy as a Database Invariant

RubySec 

GHSA-j7xr-4g94-r9h3 (graphql): Authorization Bypass in Execution::Next

Passenger - Phusion Blog 

Passenger 6.1.8

Posts on Kevin Murphy 

ActiveModel Conditional Validations

Posts on Kevin Murphy 

Frequently Played July 2026

RubySec 

GHSA-4825-p4xm-pcf2 (spree_api): Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)

danielabaron.me RSS Feed 

How I Stopped Running out of Tokens

Rails Revelry 

Why N+1 Queries Are a Natural Result of Lazy Loading

Ruby on Rails: Compress the complexity of modern web apps 

What time is it? Rails time!

RubySec 

CVE-2026-50276 (datadog): dd-trace-rb - Improper parsing of W3C baggage headers may lead to DoS

RubySec 

GHSA-5qhf-9phg-95m2 (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

RubySec 

GHSA-8whx-365g-h9vv (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

RubySec 

GHSA-9wjq-cp2p-hrgf (loofah): SVG `href` attribute bypasses local-reference restriction in Loofah

RubySec 

GHSA-cj75-f6xr-r4g7 (rails-html-sanitizer): Possible XSS vulnerability with certain configurations of rails-html-sanitizer

Julia Evans 

Learning a few things about running SQLite

Remote Ruby 

Dont Steal Our Business Idea

Hi, we're Arkency 

3 example process managers in Rails

Awesome Ruby Newsletter 

💎 Issue 530 - Rebuilding My Homelab with Compose, Ruby, IPv6, and No Kubernetes

Planet Argon Blog 

When You Build Fast, People Get Lost: Rethinking My Steward Registry's Onboarding Journey

Aha! Engineering Blog 

How do you stay familiar with the code when it's written by an LLM?

Ruby Weekly 

Matz's 'Extreme Vibe Coding' opens RubyConf

Rails Designer Blog 

Add newsletter subscriptions to Rails 8 signups

Ruby News 

Ruby 3.3.12 Released

RubySec 

CVE-2026-45086 (decidim-demographics): Decidim - Forms admin question editor lacks authorization

RubySec 

CVE-2026-45330 (decidim-verifications): Decidim - Verification admins can access supplied IDs from other organizations

RubySec 

CVE-2026-45376 (decidim-admin): Decidim - Admin user search allows SQL injection through similarity-based sorting

RubySec 

CVE-2026-45377 (decidim-core): Decidim - Private exports can be downloaded through reusable links