Rubyland

news, opinion, tutorials, about ruby, aggregated
Sources About
RubySec 

GHSA-r766-3v88-pfcf (where_is_waldo): where_is_waldo authenticates ActionCable connections from a client-supplied subject_id when no authenticate_proc is configured

tekin.co.uk 

Overriding Rails’ default validation error message format

tekin.co.uk 

10 Things You Might Not Know About Rails i18n

Julik Tarkhanov 

Have less stuff

Ruby on Rails: Compress the complexity of modern web apps 

Happy Anniversary Rails!

SINAPTIA 

Ruby Argentina July meetup

Ruby on Rails: Compress the complexity of modern web apps 

New Rails reference app library published

avdi.codes 

https://avdi.codes/175297-2/?utm_source=rss&utm_medium=rss&utm_campaign=175297-2

Remote Ruby 

A Deep Dive into GitHub Actions

Awesome Ruby Newsletter 

💎 Issue 531 - RubyGems.org security advisory: Possible leak of legacy API keys via improper cache configuration

Saeloun Blog 

Rails 8 Introduces Kamal 2 For Zero Downtime Deployments

The Rails Tech Debt Blog 

Rake Beyond Rails: A Build Tool You Know

Ruby Weekly 

Why RubyGems just revoked every legacy API key

Rails Designer Blog 

Recreating Stimulus: how data-controller works under the hood

Syed Aslam 

Git Worktrees: Multiple Branches Without the Checkout Shuffle

justin․searls․co - Digest 

🎙️ Breaking Change podcast v54 - Hot Sleeper

RubyGems Blog 

Security advisory: Possible leak of legacy API keys via improper cache configuration

JRuby.org News 

JRuby 10.1.1.0 Released

SINAPTIA 

Using OpenSpec in Rails applications

The Ruby on Rails Podcast 

Episode 544: RubyConf 2026 Hallway Track

RubyGems Blog 

4.0.17 Released

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Ruby May Finally Fix the Famous “Norway Problem”

Julia Evans 

Some more things about Django I've been enjoying

RubyMine : Intelligent Ruby and Rails IDE | The JetBrains Blog 

RubyMine 2026.2: Agentic Debugging, Native GitHub Copilot Integration, Default Symbol-Based Code Insight, and More

Ruby Central 

Ruby Runway Spotlight: Paresh Sharma of Viveture

The Rails Tech Debt Blog 

Automate Tech Debt Audits with Claude Code

Evil Martians 

Which AI actually reads your site? Two months of LLM traffic, measured

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Beyond tenant_id: Treating Multi-Tenancy as a Database Invariant

Passenger - Phusion Blog 

Passenger 6.1.8

Posts on Kevin Murphy 

ActiveModel Conditional Validations

Posts on Kevin Murphy 

Frequently Played July 2026

danielabaron.me RSS Feed 

How I Stopped Running out of Tokens

Ruby on Rails: Compress the complexity of modern web apps 

What time is it? Rails time!

RubySec 

CVE-2026-50276 (datadog): dd-trace-rb - Improper parsing of W3C baggage headers may lead to DoS

RubySec 

GHSA-5qhf-9phg-95m2 (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

RubySec 

GHSA-8whx-365g-h9vv (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

RubySec 

GHSA-9wjq-cp2p-hrgf (loofah): SVG `href` attribute bypasses local-reference restriction in Loofah

RubySec 

GHSA-cj75-f6xr-r4g7 (rails-html-sanitizer): Possible XSS vulnerability with certain configurations of rails-html-sanitizer

Julia Evans 

Learning a few things about running SQLite

Remote Ruby 

Dont Steal Our Business Idea

Hi, we're Arkency 

3 example process managers in Rails

Awesome Ruby Newsletter 

💎 Issue 530 - Rebuilding My Homelab with Compose, Ruby, IPv6, and No Kubernetes

Planet Argon Blog 

When You Build Fast, People Get Lost: Rethinking My Steward Registry's Onboarding Journey

Aha! Engineering Blog 

How do you stay familiar with the code when it's written by an LLM?

Ruby Weekly 

Matz's 'Extreme Vibe Coding' opens RubyConf

Rails Designer Blog 

Add newsletter subscriptions to Rails 8 signups

Ruby News 

Ruby 3.3.12 Released

RubySec 

CVE-2026-45086 (decidim-demographics): Decidim - Forms admin question editor lacks authorization

RubySec 

CVE-2026-45330 (decidim-verifications): Decidim - Verification admins can access supplied IDs from other organizations

RubySec 

CVE-2026-45376 (decidim-admin): Decidim - Admin user search allows SQL injection through similarity-based sorting

RubySec 

CVE-2026-45377 (decidim-core): Decidim - Private exports can be downloaded through reusable links

RubySec 

CVE-2026-45378 (decidim-verifications): Decidim - Verification documents can be downloaded through reusable links

RubySec 

CVE-2026-45414 (decidim): Decidim - JWT-backed authentication can be replayed across organizations

RubySec 

CVE-2026-45415 (decidim-verifications): Decidim - CSV census record endpoints improper authorization

RubySec 

CVE-2026-45572 (decidim-core): Decidim - HTML content blocks allow stored script execution

RubySec 

CVE-2026-45573 (decidim-core): Decidim - Push subscriptions can be abused for server-side requests

Ruby Central 

Announcing the RubyGems.org Supporters Program in Japan

Tenderlove Making 

Detecting Full Table Scans With SQLite

The Rails Tech Debt Blog 

Rails 8.1: Deprecated Associations

OmbuLabs.ai 

Do LLM Benchmarks Predict Good Agents?

The Ruby on Rails Podcast 

Episode 543: Mike Dalton and Authentication Hell

Radan Skorić's website 

When broadcasting a Turbo refresh is not enough: faster UX with versioned immediate updates

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

⚽ World Cup Fever Hits the Ruby Community

Evil Martians 

The joy of Inertia Rails: painting your own with 50 happy little lines

Island94.org 

Planning badly, more and less

The Bike Shed 

506: The Muppet Software Team

OmbuLabs.ai 

Case for AI powered Data Pipelines

DEV Community: Masataka Pocke Kuwabara 

Never Escape This Ruby Loop. Also, Here's How.

Ruby News 

Ruby 4.0.6 Released

Gusto Engineering - Medium 

Taste Over Tooling: Craftsmanship in the Post-Execution Era

tekin.co.uk 

10 Things You Might Not Know About Rails i18n

The Rails Tech Debt Blog 

From AI Opportunity to AI Feature in Rails

André Arko 

jj sales pitch

Tim Riley 

Continuations 2026/28: Bloom of the undying

Charles Oliver Nutter 

JRuby at RubyConf 2026

Remote Ruby 

The Great Falcon Defense and CI Innovations

Ruby on Rails: Compress the complexity of modern web apps 

Date.this_quarter? and more

RubyGems Blog 

4.0.16 Released

Awesome Ruby Newsletter 

💎 Issue 529 - Reverse-engineering Codemasters' BIGF archive format in Ruby

The Rails Tech Debt Blog 

Open-Source APM Tools for Rails

Ruby Weekly 

Getting Mastodon on Spinel

RailsCarma – Ruby on Rails Development Company specializing in Offshore Development 

Top 20 Web Development Companies in India 2026

Rails Designer Blog 

Permission UI the Rails way

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Why Ruby’s Issue Tracker Still Links to a 1991 Paper About Floating-Point Numbers

Robby on Rails 

What Happens When Your Dotfiles Get Ideas

SINAPTIA 

Building an AI-powered commercial intelligence dashboard

The Rails Tech Debt Blog 

Migrating from Secrets to Credentials

Evil Martians 

Storybook Workbench: audit vibe-coded UIs and find hidden bugs in hours

Rémi Mercier 

Let's talk about tools (Ruby Stained Glass Notes #04)

The Ruby on Rails Podcast 

Episode 542: Kyle D'Oliveira and the Fibonacci Funhouse

Planet Argon Blog 

Your Solo Developer Deserves Backup

Ruby Central 

Recharge at RubyConf with Fullscript

Judoscale Dev Blog 

Judoscale on Tour: Render Has the Pieces, Not the Workflow

Ruby on Rails: Compress the complexity of modern web apps 

Calling All RUG Organizers: Want to MC Rails World this year?

The Bike Shed 

505: What is a “principal” or “staff” engineer?

dmitrytsepelev.dev 

Surviving rolling deploys when Sidekiq meets a class it doesn’t know yet

RubySec 

GHSA-52jp-gj8w-j6xh (mcp): Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

RubySec 

GHSA-5p9g-j988-pcwv (mcp): Ruby SSE Session Poisoning

RubySec 

GHSA-7683-3w9x-ch42 (mcp): Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

RubySec 

GHSA-h669-8m4g-r2hc (mcp): Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

RubySec 

GHSA-rjr6-rcgv-9m7m (mcp): Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

Passenger - Phusion Blog 

Passenger 6.1.7

RubySec 

CVE-2026-54696 (json): JSON generator heap buffer overflow when streaming to an IO

RubySec 

CVE-2026-38969 (webrick): ruby webrick through v1.9.2 WEBrick reparses trailer

André Arko 

Meet Spinel

Tim Riley 

Continuations 2026/27: Hanami 3.0!

danielabaron.me RSS Feed 

Audit a Rails Project with the Thoughtbot Audit Skill

Drifting Ruby Screencasts 

Claude Skills

RubySec 

GHSA-mjgf-xj26-9qf9 (pay): pay-rails/pay - non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

Tejas' Blog 

Distributive Conditional Types in TypeScript