GHSA-3553-vcg5-72jw (dalli): Unbounded decompression and reply sizes allow memory exhaustion
GHSA-4qp6-2jcr-596v (dalli): Routing tokens can inject meta protocol flags, and failed requests can retry forever
GHSA-m252-9cgf-vx2w (dalli): With a namespace, a retried request reads or writes a different key
GHSA-p6pm-ch9v-44vx (dalli): Pipelined get_multi can return another key's value after an error reply
GHSA-w39f-xq2m-4g8x (dalli): Forking can resend buffered memcached requests and desynchronize the parent's connection
GHSA-wr87-m4jw-29x5 (dalli): Per-request raw and the JSON serializer don't prevent unsafe deserialization
I was in the audience at Rails World 2026 when Aaron Patterson (tenderlove) kicked off the closing keynote. Aaron opened with a well-worn line: “the purpose of a system is what it does.” He wasn’t satisfied with it. The purpose of a system, he argued, is what it does for whoever is observing it.
Hand an old Nokia 3310 to someone who has never seen a cell phone before, and they might use it as a hammer. In that moment, to that person, it is a hammer. What a system does depends on who’s watching.
That distinction has a name in compiler design: The as-if rule.
In this post, we’ll walk through what the as-if rule means for Ruby’s compiler, where Ractors push it right up to its edges, and how…
Joël takes Bike Shed out onto the conference floor at RailsWorld as he interviews programer and streamer Rachael Wright-Munn, aka ChaelCodes.
Rachael talks about her efforts to index all ruby events around the world with RubyEvents.org, how she augments her workflows with years old generators rather than LLMs, the rising cost of tokens and why AI may not always be your best solution to a problem.
—
Keep up to date with all things Ruby conferences, past and future, with Rachael’s index at RubyEvents.org
Read more about the SPIDR approach Rachael mentioned.
Our guest for this episode was Rachael Wright-Munn, connect with her on LinkedIn or check out her website to follow along…
Your host for this episode has…
Gusto Went to LDX3 NYC
In September, Gusto attended LDX3 NYC — a conference entirely dedicated to leadership in tech. There were managers, directors, tech leads, and senior engineers. Attendees jumped between the technical and management stage, learning about “Re-engineering the software development playbook” on the management stage one hour and “How to kill the code review” on the technical choices stage the next.
The one thing we had in common: everyone there was invested in learning how to become a better leader.
📸 Pictured left to right: Kamilah Taylor, Vianca Martinez, Tori Huang, Rebecca Borison, Irina Khafizova, Anshuma Chandak (and Alyssa Hester here in spirit!)Because, of course, AI. Everything is changing…
Today we are releasing Hot Cell v1.0, a suite of gems that moves Active Storage’s attachment processing out of your Rails application and into an unprivileged sidecar container with no network, no credentials, and nothing on its filesystem worth stealing. Adopting it is a configuration change, not a code change. It is already running in production at 37signals, in Basecamp, HEY, and Fizzy.
I introduced Hot Cell at Rails World 2026 in a talk titled “Hot Cell: Securing Active Storage in the age of AI.” What follows is basically that talk, written down, plus a couple of things that have changed since then. (If you’d rather watch the video or flip through the slides, go for it.)
Where we are
…🎙️ Breaking Change podcast v56.0.1 - Zach Holman wants more of everything
Direct link to podcast audio file
Zach Holman, founder of Signed, joins me for another 🔥Hotfix🔥. Zach wants more of everything. Let's see what we can do about that.
Write into the show at podcast@searls.co.
Show notes:
CVE-2026-67987 (ruby_llm): Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2026-67989 (ruby_llm): Polynomial-Time Regular Expression Denial of Service (ReDoS) vulnerability
Continuations 2026/40: Green on JRuby
Heckuva week.
Hanami Minitest had started failing its scheduled builds due to our ongoing work on Hanami’s reloading support. I fixed it here and here. (Why do I mention such small things here in my weeknotes? Because these are just as important aspects of maintenance as everything else—fixing broken windows—and it all takes time.)
Adam merged Alexander’s transient attribute support into Rom Factory, a very handy improvement!
Adam also finished updating Rom Factory for our repo-sync, and I followed up by preparing it for automated releases. With that done, I released v0.14.0!Nice to see a few things from Sean this week. First, in Hanami Action: I reviewed and merged his fix to handle…
RubyLLM 2.0 is the biggest release since 1.0. It starts with tool approval:
class RefundOrder < RubyLLM::Tool
description "Refunds an order"
parameter :order_id, description: "ID of the order to refund"
requires_approval # that's all it takes
def execute(order_id:, tool_call: nil)
Refunds.issue(order_id:, idempotency_key: tool_call.id)
end
end
class SupportAgent < RubyLLM::Agent
chat_model Chat
tools RefundOrder
end
chat = SupportAgent.create!
chat.ask "I was charged twice for order 42." # stops before refunding
# later, when the user approves
chat = SupportAgent.find(chat.id)
chat.approve(chat.pending_approvals.first)
chat.complete # issues the refund and answers
T…
Last week the topic on everyone's mind seemed to be the future of programming. All my friends were talking about it, people I follow were talking about it, and I was thinking about it as well. Then David's (DHH's) Rails World keynote turbocharged the conversation.
His talk didn't come as a surprise to me. I was a week into rewriting HEY in Rust during Rails World. And "Pencils down" only codified how we'd been working for months at that point.
David is right. Like it or not, we programmers, like painters before us, are slowly going to disappear. AI, like the camera, completely changed the game. You can sulk about it, or you can pick up a camera, start learning, and become a photographer.
…Short URLs
Resolvers Have Types Too
In The Browser Half I looked at the part of a Hotwire app where nothing checks anything: the strings that wire Stimulus controllers to each other and to Ruby. A GraphQL server is the opposite case. Its contract is already typed and explicit, and graphql-ruby validates every incoming query against it.
What it doesn't check ahead of time is the other side: whether the Ruby behind each field returns what the field declares. A field declared null: false that comes back nil, or a field with no method behind it, is found when a request reaches it. That's the half Roundhouse can see, because it already infers the types of a Rails app's Ruby without annotations.
Following the schema down
A…
kamal-backup 1.1 adds dump, which downloads one database dump from your backups without running a restore:
bundle exec kamal-backup dump latest -o tmp/app.pgdump
It works with PostgreSQL, MySQL, MariaDB, and SQLite. Use it to look at production data locally, to give someone a dump to debug against, or to load a backup into a tool that expects a plain dump file. Before 1.1, that meant restoring somewhere first or running restic by hand inside the accessory.
How It Works
dump talks to the backup accessory over SSH, with the same user, port, proxy, and keys Kamal already uses from config/deploy.yml. The accessory reads its own mounted repository config, so your restic credentials never…
For Rails applications, you probably want to serve HTML5, and you only want to support browsers that support HTML5. And even if you must support older browsers, you probably want to make sure your application works for HTML5-compliant browsers.
If you’re using Capybara with the Selenium driver, this will happen automatically if the headless browser is HTML5-compliant. This introduces some overhead, so I try to use the Rack::Test driver if I can get away with it. Unfortunately, when using the Rack::Test driver, Capybara processes the HTML as HTML4. This can hide bugs in your HTML.
For example, when nesting button_to inside a form_for block, the form end tag emitted by button_to will close…
Generated Rails
Hifumi generates a complete Rails application from a natural-language prompt. It runs a plain rails new, then a planning model breaks your request into revisions and Claude agents write each one. The prompt steers them toward a default Rails 8 app: Tailwind and Hotwire, the default Gemfile, and sign-in via has_secure_password plus sessions rather than Devise. Each revision has to pass a verify loop before it's committed: bundle check, db:prepare, zeitwerk:check, a smoke test that requests every static GET page, and rails test. What you get at the end is an ordinary Rails repository, yours to keep.
Roundhouse reads a Rails app and compiles it, to Ruby, to native code via Spinel, and to a…
If you write software for a living, you’ve probably been told some version of this lately: the code doesn’t matter anymore. The AI writes it now. Your job is to think like a product manager, or a QA engineer, or a “maker” who describes what they want and lets the machine figure out the rest.
I don’t buy it. You’re a programmer, and that’s a great thing to be.
Things are changing radically and rapidly, but the essence of programming remains. There is still such a thing as a better architecture, a solution that better fits the problem. There is still such a thing as well-modeled and well-factored code. There is still such a thing as a great abstraction, one that gives you leverage and…
In 1997 I wrote UcsLink.Fusion for the University of Geneva. We had hundreds of PCs across the city, Sun and Windows NT servers, and Windows 95 and Linux workstations. Getting a user’s software and settings onto whichever PC they sat down at was a job for login scripts. I wrote a Delphi 2.0 application to do it instead.
UCS stood for Universal Copy System. Fusion read a script that mapped network drives, copied shared software, created shortcuts, connected printers, set environment variables and synchronized the clock. It could include other scripts, test conditions and clean up files left by a previous run. The surviving configuration maps a personal drive, a software drive and a group…
The Way and Remainder

1970 - 2024: BCC Era (Before Claude Code)
Writing software in the “before times” was an iterative process, evolving from punching holes in paper all the way to clacking away on custom, clicky mechanical keyboards.
Through variations of this process, the steps were mostly the same:
- Understand the problem
- Come up with a solution
- Break the solution into parts
- Write code that solves each part
- Test that new things work
- Test that old things still work
- Repeat as needed
As time went on, patterns emerged. Then those patterns were overused and new patterns took their place. Programming dogma went from “everything can be functional programming” to “nothing can be functional…
The Browser Half
In As If I compared two ways of making Campfire fast: compiling the Rails app with Roundhouse, and porting it by hand to Rust, as 37signals did with once-campfire-rust. Both check their output against the running Rails app. Both are, it turns out, ports of the server only.
Campfire's app/javascript is 3,749 lines. Its models are 1,375 and its controllers 1,325, so the JavaScript is larger than both together. Roundhouse copies it into the output byte for byte. The Rust port serves the Rails app's JavaScript too, and shadows exactly three files.
A bug both ports shipped
One of the Rust port's three overrides is base_autocomplete_handler.js, and its OVERRIDES.md says why: the original calls
fe…CVE-2026-12545 (hammer_cli): hammer_cli - Insecure interpolation of the $EDITOR environment variable
Direct link to podcast audio file
Matt Swanson had me back on YAGNI to talk about the fallout from DHH's Rails World keynote and what it means for your weekend. We discuss what happens to the "one-person framework" when agents write the code, how frustrating it is when something is absolutely correct but still misses the point, and how I've accidentally constructed a dark factory with agents building and maintaining my iOS apps.
We also get into what I'd tell developers who are worried about where all this is heading and why World of Warcraft is my dark horse candidate to beat Grand Theft Auto 6 in November.
Appearing on: YAGNI
Published on: 2026-10-02
Original URL: https://share.tr…
Comments? Questions? Suggestion…
Hi, it’s Greg. Let’s explore this week’s changes in the Rails codebase.
The Rails World talk recordings are online
Blazing fast, one week after the event, you can watch all the talks from Rails World on YouTube!
“Autoloading and Reloading” guide community review
The updated “Autoloading and Reloading” guide is ready for community review. Please have a loook and give feedback.
Bump minimum Ruby version to 3.3.5
This commit bumps the minimum Ruby version to 3.3.5 so the WeakKeyMap polyfill can be removed, which would allow using non-Thread/Fiber/etc. as keys, and enable a refactor to prevent iterating over every connection pool.
Look at all the things he's not doing
There’s a moment in the early seasons of South Park when Cartman et al find the source of an underwear crisis in their mountain town. It’s the underpants gnomes in their cave. They have a plan.
- Collect Underpants
- ???
- Profit
I’ve been considering David’s opening Rails World keynote and realised that this is the main problem I have with it. Rails World is about “shaping the future of Ruby on Rails”. Instead what we got was opinionmaxxing: a lot of certainty about the destination, but in his own words, not much that was ‘practical’ or ‘prescriptive’ about getting there.
- The model got good at writing code
- ???
- Models write all code, we don’t need to care
There’s a vibration…
Ruby AI News - October 2nd, 2026
Welcome to the 38th edition of Ruby AI News! This edition features… well you know what we’re talking about this edition. This is a special edition, the 39th edition will follow next week.
Here We Go
There are…
Hanami, Why?: Bits & Bobs
Welcome back to my "Hanami, Why?" series. If you missed it, be sure to read Hanami, Why?: Introductions before you start this issue. It is my intent to keep these issues focused on singular subjects whenever possible. However, in today's issue we are going to cover several topics that are too small to warrant their own issue but still important to have for context. As I mentioned, Hanami has a lot of important abstractions, and today we are going to be covering what I consider "system level" abstractions. We have lots to cover, but this context will be important for a further understanding of how Hanami works.
Dependency Injection
Most of the time Ruby is pretty great at telling you what a…
Live At Rust, Uhh, Rails World 2026
Recorded live from Rails World 2026, Andrew, Chris, David, Jason Charnes, and eventually Andy Croll, unpack the strange mood surrounding this year’s conference. Much of the conversation centers on DHH’s keynote and the increasingly agent-driven future of software development: if AI can write, debug, and even understand the code for us, what happens to the value of frameworks, developer expertise, documentation, and even Ruby itself? They also dig into Hotwire, Active Search, Herb, Active Job Continuations, security concerns around AI-generated software, and what the Ruby community might rally around if the language becomes less central to how developers identify themselves. And because it’s…
Basecamp 5 runs on Puma in cluster mode: one master process with preload_app! and 63 single-threaded workers per host, deployed as a Docker container with Kamal.
We serve Basecamp from several sites. Each site has its own web hosts and a read replica of the database, and writes go to a single primary database in one of them.
On our busiest hosts, each deploy left up to 2,000 requests waiting while the new workers warmed up. We reduced those queues by running signed-in requests through the app in the Puma master, before it forked the workers.
Why 63 single-threaded workers?
Basecamp has always served web requests from processes rather than threads. It ran on Unicorn, which only does…
NWRUG's (Manchester, UK) October 2026 meeting — It's time to bin your VCR
The next North West Ruby User Group in Manchester, UK is in a fortnight on 15 October at Colony, One Silk Street. Rob Whittaker will take us through one of his hot-takes: VCR does more damage than good, and there are imperfectly better ways to stub your external requests.
Rob Whittaker is Director of Software Development at thoughtbot. He has over two decades of professional web development experience and has worked with Ruby and Rails since 2012. (He’s also the co-organizer of NWRUG!)
We’ll be at the venue for pizza from 6:30pm with the talk starting at 7pm. Afterwards we’ll retire to The Crown & Kettle for a drink. The venue, pizza, and drinks are kindly provided by NWRUG’s sponsors Fat…
YAGNI: Camping Chair Development
I joined Matt Swanson on YAGNI to talk about how I build software now across Fireside, Flipper, and Box Out. Some of it even happens from a camping chair.
Some of the highlights:
I’m Not a Craftsman. I always thought of myself as a craftsman. Bespoke furniture. Samurai. Honor. All that. Then on December 14th I turned on a 20x Claude plan just to try Opus and realized nope, I just love shipping stuff and solving problems. These days I read the data models and the queries because those affect how fast things are for customers. JavaScript and view code? I don’t read it. Does it look right? Is it responsive? What’s my Lighthouse score? Good enough.
Stripping Back. I went through a phase of…
Garrett and I started a podcast. It’s called The Friday Deploy, and the tagline is the whole point: ship on Friday, sleep through the night.
We already do a marketing and business podcast for Fireside, so we figured, let’s go full on dev with this one. Feature flags, deployments, infrastructure, incidents, product decisions, and all the little practices that let you deploy whenever you want without the sweaty armpits. Sometimes it’ll be just me and Garrett, and sometimes we’ll bring on a guest to walk through what they do.
Subscribe on Apple Podcasts, Spotify, or RSS.
Episode 1: Changing the Wheels While the Car Is Moving
We’re almost exactly two years into owning Fireside, so for the…
Happy to report that in record time, all Rails World 2026 talks are now online.
While all four keynotes got everyone talking about AI, this year’s talks covered a good balance of what’s new in Rails and how Rails developers are using AI.
The AI-focused talks covered: making codebases agent-friendly, harness engineering, generators, AI pipelines in plain Ruby, agent loops driving Ractor-safety, building MCPs, and rapid deploys with the help of agents.
There were also talks about: Lexxy, Active Search, ONCE, Herb in Rails 8.2 and durable Active Job workflows, plus deep dives into Solid Cable, Hotwire, Kamal, sharding, the RubyGems compact index, and HotCell…
Every month, someone on our team was doing the same thing: pulling data from a handful of systems, assembling it into a document, and writing up a summary before it could go to the client. The work was not complicated. It was just slow, repetitive, and easy to get wrong.
That monthly report was not an isolated case. We’ve built a few internal tools around the same pattern: a repetitive workflow, data sitting in one or more external systems, and a human who needs to stay in the loop at the right moments. Each time we reach for a solution, we face the same question: how much infrastructure does this actually need?
In this post, we will look at the characteristics of a workflow that fit this…
Joy of the Craft
This collective was founded on a simple idea that you should enjoy the work you do including a strong sense of purpose in order to enrich the lives of your team and customers combined. Profit, while important to keep the lights on, is not the driving force. Building expertise and using software to make life more enjoyable for folks is much more rewarding. Plus, it feels good to wake up each morning knowing you are working in a code base that is well maintained, always up-to-date, a joy to use, and a benefit to society.
The Engineer’s Oath helps us never lose sight of our purpose while our Engineer’s Rigor keeps us honest because you can’t make an impact in life if…
Rails' next rich text editor hits 1.0
#819 — October 1, 2026
Ruby Weekly
Lexxy 1.0: Rails' New Rich Text Editor to Replace Trix — Built on Lexical and already powering 37signals' Basecamp 5, it gives you tables, Markdown shortcuts, smart links, syntax-highlighted code and mentions, and it's easy to swap into Action Text in place of Trix.
Jorge Manrubia (37signals)
💡 The Lexxy site has a sandbox demo if you'd like to try it out first.
Switching APM? One Ruby Gem Now Covers Distributed Tracing — Errors, N+1s, Sidekiq jobs, logs, host metrics and now distributed tracing (beta) in one Ruby gem. Every feature on every plan, unlimited…
I recently surprised someone by showing you can use any event besides the common click, submit and keydown events. The Stimulus docs list those seven default events and their shorthand equivalents. Enough for most cases. But the data-action descriptor is event->controller#method where you can bind to anything the DOM throws at you: native element events, global document events, even custom dispatched events. All work the same way.
I put together a small demo repo to show a handful of these in action. Lets go over them and maybe you find a way to refactor and simplify one of your Stimulus controllers.
First a few you probably have used before. A <textarea> fires input on every keystroke. The …

Regular SF Ruby Conference tickets are $450 through September 30. Meet Ruby friends, play The Pier, join small-group conversations, and explore the 2026 program in San Francisco.
Not a single person in the Ruby community has told us they go to conferences for anything other than meeting new people and catching up with old friends. Our community needs that shared warmth and joy more than ever.
But going to a conference alone can be intimidating. You walk into a room full of people you don't know, have no idea whom to talk to, and end up checking your phone between talks. We've all been…
I was in the audience at Rails World 2026 for Jenny Shen’s talk on the RubyGems Compact Index, the last technical talk before the closing keynote. Jenny is a Senior Developer at Shopify and a RubyGems.org maintainer, and she opened by asking the room who had heard of the compact index before. Not many hands went up, which was kind of the point: it’s a piece of infrastructure that handles tens of millions of requests a day, and most Rubyists never think about it.

Every time Bundler resolves your Gemfile, it’s talking to the compact index. In this post, we’ll walk through what the compact index actually is, how RubyGems.org keeps it in sync at scale, and two features Jenny helped ship in…
Hanami, Why?: Introductions
I mentioned in my Hello, world! post that I built this site using Hanami. This site may seem simple on the surface; it is, after all, just a blog. However, the backend is packed with features that help me day to day. I have built a tool that lets me cross-post to both Bluesky and Mastodon. I have a private journal where I can keep notes throughout the day. There is a custom analytics engine to provide me with insights on how well my blog posts are doing. There is a messaging backend that lets readers reach me through my contact form without cluttering my inbox. I have also built a task manager that syncs with both Linear and GitHub Issues and helps me track what I need to do. Most…
What does the future of Ruby and Rails look like as AI begins to fundamentally change how software gets built?
Recorded at Rails World, David sits down with longtime Rails community member Obie Fernandez to talk about the rapid rise of agentic development and what it means for programmers, teams, and the craft of software engineering. Obie argues that while AI can dramatically accelerate development, the industry is still figuring out how to apply the discipline, constraints, and guardrails necessary to use these tools effectively in production systems.
The conversation explores how software development may be moving to a new level of abstraction—away from carefully crafting…
4.0.22 Released
RubyGems 4.0.22 includes enhancements and bug fixes and Bundler 4.0.22 includes enhancements, bug fixes and documentation.
To update to the latest RubyGems you can run:
gem update --system [--pre]
To update to the latest Bundler you can run:
gem install bundler [--pre]
bundle update --bundler=4.0.22
RubyGems Release Notes
Enhancements:
- Add –source option to gem exec command. Pull request #9765 by Akshay Birajdar
- Keep credentials on redirects only within the same origin. Pull request #9909 by Hiroshi SHIBATA
- Validate the version field in Gem::Installer#verify_spec. Pull request #9890 by Hiroshi SHIBATA
- Installs bundler 4.0.22 as a default gem.
Bug fixes:
- Remove the…
Rust is the answer to the wrong question
Nokogiri, Loofah and Crass, Compiled
I watched Marco Roth’s talk at Rails World 2026, and it left me excited about where the Rails view layer is headed.
Marco has spent the last couple of years building Herb, an HTML-aware ERB parser that is on its way into Rails 8.2 core, and at Rails World he showed what he is building on top of it: A project called ReActionView.

ReActionView adds real reactivity to your existing .html.erb templates, no Hotwire, no Stimulus, no JavaScript you have to
write yourself. That is the part that got me.
Hotwire already does a lot for us, but it still asks you to write a Stimulus controller once the interaction gets specific, and Marco’s demo showed a page that updates itself because the…
Last month the Rails Foundation published something the Ruby on Rails community had not seen before: a leaderboard of coding agents scored on real Rails work. The first Agents on Rails report topped out at 92% in the Accuracy column for the best model tested, which is roughly what you would expect from a field of frontier models. The Rails API recall column tells a different story: it shows the share of runs where the model reached for the Rails API that a task was built around, instead of hand-rolling its own version. In that first report it ran from 8% to 35%, and a follow-up published on September 2 moved the top of the range to 41%.
Those results describe Writebook, the application the…
In January 1998, a classmate and I wrote a game. It was called “Bolongas zBalls”, and it was a Java applet.
You click to start, then move the mouse, without clicking. Touch the dark ball to blow it up, and the next ball turns dark. Clear them all and the next level doubles the number of balls. Touch a plain ball and it spawns another one, so if you’re sloppy, the balls multiply until you lose. Each level has a time limit.
The intro music is the theme song from Capitaine Flam, the French version of the Japanese cartoon Captain Future, which aired on TF1 in 1981. I honestly don’t remember why we used it, nor why the game is called “Bolongas”.
Applets were removed in JDK 26, which is…
In July 1998, the Internet Society held INET ‘98, “The Internet Summit”, at Palexpo in Geneva. The University of Geneva provided about 250 computers for the conference, and I was a student there. I wrote much of the conference network’s website, www.inet98.ch, and the launcher that ran on the public Windows 95 PCs instead of Explorer.

The Inet 98 Launcher was a full-height bar on the left of the screen with a button for each installed application: Internet Explorer, Netscape, PC Pine, Telnet, WS-FTP and Office 95 and 97. I wrote it in Delphi 3. It showed a screen saver when a machine sat idle, reset itself, and could reboot the PC to return it to a clean state.
It also had a…
508: The Wonders of Static Analysis
In this week’s episode of The Bike Shed, Aji and Joël dive into the distrust around the phrase ‘programmer discipline’, why you cannot just rely on willpower, and how Static Analysis tools can help with not crossing boundaries.
From competing priorities and team member changeovers to documentation not being read, things can still fall through the cracks, so having a tool that can check the ones and zeroes that you send into GitHub. So what makes Static Analysis so different to other forms of analysis? Well, you’ll have to listen to the episode to find out!
—
Mentioned in this episode:
Joel’s talk at Rails World - ‘Harness Engineering on Rails’
Justin Searle’s Standard.rb talk - …
Welcome, thoughtbot!
I’m so happy to share that thoughtbot is our newest silver sponsor!
If you’ve written Ruby for any length of time, thoughtbot has most likely helped you out. Maybe it was a blog post, an episode of The Bike Shed, one of their many open source gems, or one of the lovely humans who work there. They’ve given our community so much for so long.
Now they’re backing Hanakai too. Here’s Rob Whittaker, their director of Software Development based in the UK, on why:
thoughtbot has built web apps and open-source Ruby libraries for over 20 years. We know how much any framework depends on the people who maintain it. Ruby is stronger with a diversity of thoughts, opinions, and approaches. The…
Hardly Promethean
Last week I published What About Rails, a dive into DHH's Rails World keynote. Smarter people than me had interesting things to say about it:
You have the most powerful tool you ever had, you have become a 1000x maker, and you can't think of how to make your stack 10x better?
José Valim poses an excellent question. I tried to find an answer.
The Bottleneck Isn't Gone
They're not gonna be web apps much longer. They're gonna be native applications, because the price of developing those things has gone to damn near zero.
The move to native apps for the frontend and Rust on the backend isn't about any particular technology. It's about cost. DHH isn't the first to make this case.
Back…
I was in the audience at Rails World 2026 for Jorge Manrubia’s talk on Lexxy, a new rich text editor for Action Text. Jorge is a Principal Programmer at 37signals, and if you’ve used Active Record Encryption, you’ve used something he built.
Jorge explained why 37signals built a new editor, what Lexxy adds, and how the work opens Action Text to other editors beyond Trix, the editor that’s shipped with Action Text since day one.
In this post, we’ll walk through why Trix became a maintenance burden, why 37signals picked Meta’s Lexical framework over the more obvious open source contenders, and what Lexxy actually does differently inside Action Text.
The Problem
Trix is built on contented…
Rails at Scale, Roundhouse Performance, and AI-Era Supply Chain Security
Andrew and Chris are back with a packed episode covering everything from Rails World anticipation and Rails 8.2 to security, Ractors, AI-assisted development, and some ambitious new Ruby tooling. They dig into RubyGems recent spam-publishing incident and Trusted Publishing, look at Shopify’s push toward Ractor-safe Rails, and explore Roundhouse, a project experimenting with compiling Rails applications into entirely different target languages. They also talk about using Claude for project planning and open source maintenance, new approaches to AI beyond traditional LLMs, the surprisingly inexpensive architecture behind Turbopuffer, PlanetScale’s new TIN search extension, and Andrew’s move…
Yesterday, in Partly in the Right, I asked where the information comes from when an agent produces a result, and what checks it. Today I have a sharper version of that question, and a new piece of evidence to ask it about.
The as-if rule
Aaron Patterson's closing keynote at Rails World was about optimization, and he framed it with a rule language implementers know well. The C++ standard puts it in a footnote: an implementation "is free to disregard any requirement of this International Standard as long as the result is as if the requirement had been obeyed, as far as can be determined from the observable behavior of the program." C has the same idea without the name. The standard describes…
Before GNU Autoconf generated configure scripts, there was a DOS program called Autoconf. It let you keep one CONFIG.SYS and one AUTOEXEC.BAT, then choose among boot configurations by pressing a key.
You did not have to wait for a menu. The PC BIOS kept early keystrokes in its keyboard queue, so you could press a configuration letter before AUTOCONF.SYS had even loaded. When the driver finally ran, it found the key and continued immediately.
I did not write the original. I copied its x86 assembly source by hand from a French computer magazine. It was the first assembly program I had ever seen and the first piece of code I compiled. I spent the next three or four years extending it into my…
This was a good week for progress on our code!
A couple of tests started flaking on JRuby mid-week. I like to get on top of these pretty quickly, so I pushed up fixes to dry-monads and dry-effects. Now that we’ve achived full JRuby support across Dry, I’m very serious about making sure we keep it!
Adam has been on a tear lately. This week he added
%formatting support to the newDry::CLI::Style::Text, and prepared a built-in spinner for Dry CLI!I merged a fix to make provider usage work inside Hanami slice class bodies, and thereby restored single-file Hanami apps. Now we have a test for it, which will help ensure we don’t accidentally lose the capability again.
A few weeks ago Aaron…
Also merged a nice little bug fix from Aaron about routes helpers finding the correct URLs for routes mounted in slices.
(Have you checked out Aaron’s shiny new homepage, by the way? It’s made in Hanami!).My…
Lexxy 1.0 is here
Today we are releasing the version 1.0 of Lexxy. Lexxy is a rich text editor for Rails built on Lexical. It already powers Basecamp, Fizzy and many others, and it will become the default editor in Rails. I recently presented it in Rails World (slides, video coming soon). This is the article version of my talk.
Trix hit a wall
Trix has been our editor since 2015, and every Rails app’s editor since Action Text shipped in Rails 6. It’s small and reliable, and it has served millions of people for a decade. But in the last few years our customers kept asking for features like tables or code highlighting, and we kept struggling to deliver them. The reason is the Trix document model.
A Trix…
Partly in the Right
On Kids and Football
My father was born and raised in a village called Moldovița, nestled at the feet of the densely forested Carpathian mountains in Romania. One of my favorite tales he used to tell us about his childhood is about the Jewish kids’ football team Maccabi Moldovița. All of the boys dreamed about playing in a football team, but they didn’t even have a real ball. This didn’t stop them though, and they came up with a plan: the Schmoll shoe paste company had a sales promotion: collect 100 shoe paste caps, send them to the factory, and you’ll get a free football! The kids did their best to waste as much shoe paste as they could, which of course led to the indignation of their parents, but finally…
Hello, world!
Hello, and welcome to my new website! My name is Aaron and I have been writing software since I was thirteen years old (twenty-seven years ago). I am a senior software engineer at Credit Ninja and have worked for companies like Root Insurance and Zillow. The main focus throughout my career has been backend web development using my primary love language, Ruby. In my spare time, I contribute to the Hanakai organization, working on Hanami, dry-rb, and ROM. Over the last few years, I have also begun to fall in love with Rust and have published a handful of projects. I am from and live in San Antonio, Texas. I have four kids ranging in age from seven to twenty-two.
This will be the fourth(?)…
Hello! Recently I needed bike lights for my bike. And I remembered that I already had rechargeable bike lights that I bought ten years ago, that I hadn’t tried in a long time. I tried to recharge them, but after fully charging them, they only worked for maybe 5 minutes before they turned off again.
I don’t know much about electronics, but I’ve been curious about whether it’s possible to fix old electronics for a long time, and this seemed like the perfect repair project because I might just need to replace the battery.
So I went to the local queer makerspace where I’m a member to use the soldering iron and try to do it! I don’t know much about electronics and this post does not contain any…
6 levels of knowledge management maturity in organizations
“Zapomniałem” is Polish for “I forgot”.
On Arkency’s Slack, our main communication channel, it has been used over 1200 times.
And I truly believe I work with exceptionally organized and meticulous people.
That only confirms what I wrote in my previous post: organizations are surprisingly good at forgetting.
That post described how we maintain an organizational knowledge graph with an LLM and event sourcing.
It was about the destination.
This one is about the road that led us there.
Looking back at how we handle knowledge at Arkency, I identified 6 levels of maturity.
I presented them yesterday at Programistok in Białystok,…
GHSA-6wmv-xq9m-fmp7 (dalli): Memcached command injection through numeric arguments to incr/decr and fetch_with_lock
GHSA-42qh-8mx8-7wqm (rack-proxy): HTTP response smuggling via ambiguous backend response framing in rack-proxy 1.x
The Job Was Enqueued by Older Code
What happens to the jobs already in the queue when I rename their class?
The code change looks straightforward: rename the file, update the callers, and fix the tests.
But a job enqueued before the deploy might wait hours or days before a worker picks it up. By then, the old class is gone.
I wanted to follow that job through the rename and work out what the new release still needs to support. Keeping the old class around seems reasonable, but then we need to decide when we can remove it.
Let’s start by removing it.
Suppose we rename FulfillOrderJob to DispatchOrderJob, update every call site, and deploy. New requests now enqueue DispatchOrderJob. A job scheduled by the previous release still…
Introducing Asgard: a Thor-based task runner where tasks live in .loki files
Asgard 0.4.0 was released on September 26, 2026. It is a Ruby task runner: define tasks as methods in a .loki file, declare what each task depends on, and run them with asgard <task>. The command line is handled by Thor, so subcommands, typed options, argument validation, and generated help are all available without extra code.
The part I’d point to first is how dependencies are declared. One depends_on line says which prerequisites run one after another, which run at the same time, and in what order those groups happen. Serial, concurrent, or a mix of both, all in the same line, with no separate job-count flag…
Pencils Down: My Take on DHH’s Rails World 2026 Keynote
This week David Heinemeier Hansson opened Rails World 2026 in Austin, Texas, with a keynote that has had the Ruby community talking ever since. A few days later Matt Solt asked me, “By the way, I’m curious to know your thoughts on David’s keynote.”
I watched it. I agree with him 100%.
My reply to Matt ran longer than he probably expected, and it turned into this post.
What David said
If you haven’t seen it, the opening keynote is on YouTube. The short version: hand-writing code is no longer an economically viable skill for most programmers at most companies. He didn’t pitch that as doom. He pitched it as an inflection point.
He…
Pencils Down, Notation Up
Hi, it’s Claudio Baccigalupo with your updates on the Rails codebase.
What a week! Rails World took over Austin with more than a thousand attendees from all over the world. I was able to meet my fellow newsletter editors and to thank the amazing Amanda Perino for another successful conference.

And now… let’s see what changed on main in the last seven days.
Newly released: Rails 8.1.4 and 7.2.4
Take a look at their CHANGELOG (v8.1.4 and v7.2.4) for all the new features.
The Asset Pipeline Guide rewritten
Now with a bigger focus on how a developer would use the asset pipeline and Propshaft: check it out.
Then go read the Active Record composite primary keys guide which has also been imp…
Going Deeper into Ruby with Polished Ruby Programming, Second Edition September 25, 2026 I recently had the opportunity to review Polished Ruby Programming, Second Edition by Jeremy Evans, and the timing was particularly interesting for me. Over the last few months, I have been spending more time going deeper into Ruby and Ruby on Rails, … Continue reading Going Deeper into Ruby with Polished Ruby Programming, Second Edition
What About Rails?
David Heinemeier Hansson is, for better or worse, still in charge of Ruby on Rails. I'd love to stop paying attention to him, but I build applications with Rails, so his actions affect me and my clients. Yesterday, he gave the opening keynote at Rails World 2026, where he laid out his vision for the future of Rails.
Or that's what his talk should have done. His keynote had very little to do with Rails. Here's what he did talk about, and what it means for Rails.
The Gist of It
I have retired from being a professional programmer.
Yes, he said that. No, that doesn't mean he's stepping away from software development. He now styles himself a "maker." He now claims that English is the best…
Have you ever written a type that you appreciated so much you still think about it? Like eating a really good meal, where if you try hard enough, you can still recall the taste in your mouth. I had a mini moment of Rust joy the other day and wanted to share the experience.
TLDR: I turned an enum with N variants into N types. Nothing earth-shattering, but it made my life better.
Specifically, std::path::Component is an enum that you can get from any std::path::Path reference. Where a path can be viewed as an iterator of components. To give you an example /tmp/hello is [Component::RootDir, Component::Normal("tmp"), Component::Normal("hello")]. This enum is very handy for…
Hi everyone,
I am happy to announce that Rails 7.2.4 has been released.
As stated in the maintenance policy, this is the last release of the 7.2.x series.
Security issues and bug fixes will only be provided for the 8.0.x and 8.1.x series.
CHANGES since 7.2.3
To see a summary of changes, please read the release on GitHub:
7.2.4 CHANGELOG To view the changes for each gem, please read the changelogs on GitHub:
- Action Cable CHANGELOG
- Action Mailbox CHANGELOG
- Action Mailer CHANGELOG
- Action Pack CHANGELOG
- Action Text CHANGELOG
- Action View CHANGELOG
- Active Job CHANGELOG
- Active Model CHANGELOG
- Active Record CHANGELOG
- Active Storage CHANGELOG
- Active Support CHANGELOG
- R…
Full listing
To see the full list of changes, check out all the commits on GitHub.
SHA-256
If you’d like to verify that your gem is the same as the one I’ve uploaded, please use these SHA-256 hashes.
Here are the…
#818 — September 24, 2026
🤔 DHH opened Rails World yesterday with a keynote that may have implications for Rubyists. I know readers like and loathe DHH in equal measure, so my writeup is at the end of this issue to either read or skip as you prefer.
Ruby Weekly
Benchmarking Compiled-Away Rails on Three Rubies — Roundhouse can compile (some!) Rails apps to simpler Spinel-compatible Ruby. But how does "Rails-free" Ruby fare on CRuby, JRuby and TruffleRuby? In Sam's tests, 3-17x faster than Rails, though TruffleRuby, the fastest at running stock Rails, gains least.
Sam Ruby
💡 Want to try for yourself? Rou…
On September 15, 2026, TypeSafe announced Jev, the first of what they call System One models. The launch came with a very low price, a lot of speed claims, and the promise that it “can’t hallucinate”. The obvious first question is whether this is just another Large Language Model (LLM) with a smaller bill.
It isn’t, and the reason is more interesting than the price. In this article, we’ll look at what Jev actually is, what it isn’t, and why that difference matters when you decide where AI belongs in your software.
A quick note on where this comes from: Jev launched in early access. This post is based on a careful reading of TypeSafe’s announcement and documentation, and I’ll point out the…
Hi everyone,
I am happy to announce that Rails 8.1.4 has been released.
CHANGES since 8.1.3
To see a summary of changes, please read the release on GitHub:
8.1.4 CHANGELOG To view the changes for each gem, please read the changelogs on GitHub:
- Action Cable CHANGELOG
- Action Mailbox CHANGELOG
- Action Mailer CHANGELOG
- Action Pack CHANGELOG
- Action Text CHANGELOG
- Action View CHANGELOG
- Active Job CHANGELOG
- Active Model CHANGELOG
- Active Record CHANGELOG
- Active Storage CHANGELOG
- Active Support CHANGELOG
- Railties CHANGELOG
Full listing
To see the full list of changes, check out all the commits on GitHub.
SHA-256
If you’d like to verify that your gem is the same as…
In his Rails World 2026 keynote DHH talks about one-shot apps built almost instantly with an agent as part of Omarchy. His canonical example is Omacalc, a dead simple calculator. It’s a good demo and not a hard problem. Let’s take it further and rewrite a more advanced calculator in Rust that we can also run as an MCP server, so an AI coding agent can outsource arithmetic to it instead of hallucinating a square root.
In 1994 I wrote an expression evaluator for a lab assignment. It grew into Expression Calculator, a shareware Windows app I sold through a company I co-founded, Vestris Inc. In 1997 it got pressed onto a CD-ROM and sold 3,000 copies in Germany under the name Global Calculator.…
This is the last article of a series where I introduce Attractive.js 1.0.0 (in pre-release now).
- Attractive.js 1.0.0: interactive HTML without one line of JavaScript
- Custom Actions in Attractive.js: one interface, from small to big
In this last article I want to highlight how Attractive can be a nice addition and in some cases a complete replacement for Hotwire.
I created a simple message board in Rails. No Stimulus anywhere, nor Turbo Streams. Check it out!

Most of the features of the is build one Attractive extension I intentionaly left out last week; Attract. It serves two purposes:
- intercept form request and send fetch instead (we know that technique!), and:
- work with attract JSON…
One partial, three…
I write a lot, and I use AI a lot. But AI does not write my blog posts. Mostly.
AI is useful for making some of my writing less tedious. Recently, I asked GitHub Copilot CLI to read a few dozen posts from this blog and derive a VOICE.md to assist my writing. The result is now checked into this repo and linked from AGENTS.md, so any AI agent working here gets the same reminder: this blog is authored by me, not by AI and the agent’s job is to help me rather than pretend to be me.
The useful and interesting part of VOICE.md was how it captured my weirdly specific patterns.
- Start with a real story, failure, command, bug, or piece of data.
- Say the opinion early.
- Provide examples, pull…

AI has made implementing and enforcing design systems cheaper than ever. At the cost of speed, this falls through the cracks. But agentic development makes good design system practice non-negotiable. Implement a design system and bring consistency to an existing project.
AI has made implementing and enforcing design systems cheaper than ever. Yet, at the cost of speed, this critical element falls through the cracks. But with agentic development, good design system practice is now non-negotiable. In this post, learn what to do in order to implement a…
Once a team stops trusting leaderboards, the next move is usually to build an evaluation of its own. We’ve argued before that benchmark scores are a poor predictor of production agent performance, and the natural follow-up question is what to measure instead.
Two answers come up almost every time, because they are the two cheapest evals to stand up. The first is a panel of LLM judges: ask several models whether an output is factually supported, and take the majority vote. The second is step-level grading: walk the agent’s trajectory one step at a time, score each step, and blame the first one that looks wrong. Neither needs labeled data, and both can be running by the end of the week.
Thr…
David is joined by Javier Cervantes, co-creator of the Ruby User Forum, to discuss the origins of the project and the need for a persistent gathering place for the Ruby community. After returning to Ruby following several years working with other technologies, Javier found an active ecosystem that was nevertheless scattered across newsletters, blogs, Slack communities, Discord servers, social networks, and individual open-source projects. That experience eventually led to the creation of the Ruby User Forum as a place where conversations can happen more slowly, remain searchable, and continue over days or weeks instead of disappearing into a chat history.
Javier shares what the…
Ruby 3.4.11 Released
Ruby 3.4.11 has been released. This is a regular scheduled update release includes bugfixes.
Please see the GitHub releases for further details.
Download
-
https://cache.ruby-lang.org/pub/ruby/3.4/ruby-3.4.11.tar.gz
SIZE: 22492449 SHA1: ed687c91e79b20a755666adbc290695accd49d79 SHA256: 5c22be44524312b3d433d68739bcc530633b1da5ef8ba0afa0a37680da17d3de SHA512: cb951af61fb237ddf3213f5efec893a50524216800359514baded26189a5aa1640cc83e344aedd001cc57c4479cfabcf20033be77c28401333f57f2ac13c6640 -
https://cache.ruby-lang.org/pub/ruby/3.4/ruby-3.4.11.tar.xz
SIZE: 16712500 SHA1: c36b1142f3d45441edbe0bb9146ddda39b018065 SHA256:…
Herb on Rails
ERB does not know that it is generating HTML. It finds the <% %> tags, evaluates the Ruby inside them, and concatenates everything else as plain text. Whether the result is valid markup has never been its problem.
Herb changes that. On August 25, 2026, the Ruby on Rails core team merged Add Herb as an HTML-aware ERB implementation, which brings in Herb, an ERB implementation that parses HTML and ERB into a single syntax tree and uses Prism for the Ruby inside the tags. Broken markup can now fail while the template compiles, instead of reaching a browser.
In this article, you will learn what Herb is, how to audit your own views with it today, what it can fix for you, what it cannot, and…
When we talk about building with AI, most of the attention goes to what’s new. Models, agent frameworks, protocols, and tools seem to appear every week, making it easy to assume that adopting AI means introducing an entirely new technology stack.
But Rails developers already have many of the building blocks needed to create useful AI-assisted workflows. Generators, Rake tasks, command-line interfaces, schemas, tests, and APIs were designed to make software easier to work with by providing structure and predictable behavior. Those same qualities make them well suited for AI coding tools.
In this context, an AI-assisted workflow doesn’t mean building an agent into a Rails application. It…
Campfire, Three Rubies
Three days ago I ran the five-endpoint blog fixture through a 2×3 — stock Rails and Roundhouse's emitted Ruby, each on CRuby+YJIT, JRuby and TruffleRuby — and the result inverted June's: Graal rewarded stock Rails 3.4× and the emit only 1.8×, because a runtime that specializes the interpreter to the program is already doing much of what a compiler that specializes the framework to the application does. The post ended by saying the next experiment was Campfire, Basecamp's chat app, on the same three runtimes, and that TruffleRuby's lack of fork would make it a different experiment.
It is a different experiment, and it has a different answer.
Correction, a few hours after publishing. The…
Extralite 3.1.0 is Here!
I’ve just released of Extralite version 3.1.0. This new release implements automatic caching of parametric queries, and updates the bundled SQLite to version 3.53.4.
Extralite is a fast and innovative SQLite wrapper for Ruby with a rich set of features. It provides multiple ways of retrieving data from SQLite databases, makes it possible to use SQLite databases in multi-threaded and multi-fibered Ruby apps, and includes a comprehensive set of tools for managing SQLite databases.
Automatic Query Caching
Extralite now automatically caches the underyling sqlite3_stmt object for any
parametric query. Previously, when you ran the same SQL using
Database#query_xxx with different parameters,…
JRuby 10.0.7.0 Released
The JRuby community is pleased to announce the release of JRuby 10.0.7.0.
- Homepage: https://www.jruby.org/
- Download: https://www.jruby.org/download
JRuby 10.0.x targets Ruby 3.4 compatibility.
Thank you to our contributors this release, you help keep JRuby moving forward! @aminmansuri, @evaniainbrooks, @gillesbergerp, @jwils, @kares, @lloeki
Notable Changes
Performance
- Fixed a regression in startup time on MacOS by properly loading native JNR subsystem. #9688, #9689
- Improve performance of autoloads overridden by an actual require. [#9677], #9675
Java Integration
- The location of the AppCDS JSA file can now be specified with JRUBY_JSA_HOME. #9667
Standard Library
Def…
JRuby 10.1.2.0 Released
The JRuby community is pleased to announce the release of JRuby 10.1.2.0.
- Homepage: https://www.jruby.org/
- Download: https://www.jruby.org/download
JRuby 10.1.x targets Ruby 4.0 compatibility.
Thank you to our contributors this release, you help keep JRuby moving forward! @aminmansuri, @drzaiusx11, @evaniainbrooks, @gillesbergerp, @jcharaoui, @jwils, @kares, @lloeki, @makenowjust, @nobu, @sampokuokkanen, @shugo
Notable Changes
Compatibility
- Multiple fixes for fibers and fiber scheduler support. #9604, #9607, #9622, #9645, #9649, #9656, #9660
Performance
- Fixed a regression in startup time on MacOS by properly loading native JNR subsystem. #9690
- Improve performance of…
In the Stage 2 report we shipped 20 feature tickets on Fizzy and promised to explore benchmarking the agents all on max-effort. Now we have run it: every model on the board, same tickets, reasoning turned all the way up. We also tested a new model: DeepSeek 4.1 Flash.
The short version:
- Effort matters, but only with some agents. GPT-6 Astra (already in first place) went from 35% to 53% success, GPT-5.6 Sol improved from 18% to 28%, and GPT-5.6 Luna performed much better: from 0% to 27% success. Claude, Gemini and Grok barely moved, and Gemini regressed. Muse doubled, from 10% to 20%.
- It costs. The max sweep cost about $4,100 across all models against $2,250 for the defaults, and runs…

Introduction
As products and engineering organizations grow, their API grows with them. New features get shipped, old design patterns coexist with new ones, and decisions that once felt obvious become harder to apply consistently across the entire organization.
At a small scale, maintaining a high-quality API is mostly a matter of shared taste and close collaboration between engineers. At a larger scale, it becomes a systems problem.
How can an organization keep API design consistent and high quality when dozens or hundreds of engineers are making schema changes across many distinct product domains? How do you make sure new APIs follow best practices? And just as importantly, how do you find…



