All Articles

Rails World '26: Hot Cell for Active Storage

I was in the audience at Rails World 2026 when Mike Dalessio, a Rails Core team member who joined earlier this year, put up a slide that said “You are not worried enough (probably).”

He had good reasons to say it.

This summer, Mike handled CVE-2026-66066 opens a new window , an Active Storage vulnerability that let a crafted image upload read files from the server, including your application’s secrets.

His talk, Hot Cell: Securing Active Storage in the age of AI opens a new window , was half post-mortem and half proposal: if we can’t stop image libraries from being vulnerable, maybe we can stop their vulnerabilities from reaching our secrets.

In this article, you will learn what that CVE actually meant, why patching image libraries is no longer enough, how Hot Cell sandboxes Active Storage, and whether you can use it in your Rails application today.

Read more of Rails World '26: Hot Cell for Active Storage opens a new window

Rails World '26: The As-If Rule, Ractors & AI

I was in the audience at Rails World 2026 when Aaron Patterson (tenderlove) kicked off the closing keynote. Aaron opened with a well-worn line: “the purpose of a system is what it does.” He wasn’t satisfied with it. The purpose of a system, he argued, is what it does for whoever is observing it.

Hand an old Nokia 3310 to someone who has never seen a cell phone before, and they might use it as a hammer. In that moment, to that person, it is a hammer. What a system does depends on who’s watching.

That distinction has a name in compiler design: The as-if rule.

In this post, we’ll walk through what the as-if rule means for Ruby’s compiler, where Ractors push it right up to its edges, and how the same idea explains a real RubyGems.org security incident that played out earlier this year.

Read more of Rails World '26: The As-If Rule, Ractors & AI opens a new window

Rails World '26: The RubyGems Compact Index

I was in the audience at Rails World 2026 for Jenny Shen’s talk on the RubyGems Compact Index, the last technical talk before the closing keynote. Jenny is a Senior Developer at Shopify and a RubyGems.org opens a new window maintainer, and she opened by asking the room who had heard of the compact index before. Not many hands went up, which was kind of the point: it’s a piece of infrastructure that handles tens of millions of requests a day, and most Rubyists never think about it.

Read more of Rails World '26: The RubyGems Compact Index opens a new window

Rails World '26: Herb and ReActionView

I watched Marco Roth’s talk at Rails World 2026, and it left me excited about where the Rails view layer is headed.

Marco has spent the last couple of years building Herb, an HTML-aware ERB parser that is on its way into Rails 8.2 core, and at Rails World he showed what he is building on top of it: A project called ReActionView opens a new window .

Read more of Rails World '26: Herb and ReActionView opens a new window

Run the Rails Agent Benchmark Yourself

Last month the Rails Foundation published something the Ruby on Rails community had not seen before: a leaderboard of coding agents scored on real Rails work. The first Agents on Rails report opens a new window topped out at 92% in the Accuracy column for the best model tested, which is roughly what you would expect from a field of frontier models. The Rails API recall opens a new window column tells a different story: it shows the share of runs where the model reached for the Rails API that a task was built around, instead of hand-rolling its own version. In that first report it ran from 8% to 35%, and a follow-up published on September 2 opens a new window moved the top of the range to 41%.

Those results describe Writebook opens a new window , the application the benchmark runs against. They do not describe your application. On August 24 the Rails team open sourced lemans opens a new window , the harness behind every number they have published, which means you no longer have to take the leaderboard’s word for anything.

In this article, you will learn what lemans measures, how to build a small bench you can run on your own machine, and how to prove that bench is worth trusting before you spend anything on it.

Read more of Run the Rails Agent Benchmark Yourself opens a new window

Rails World '26: Lexxy for Action Text

I was in the audience at Rails World 2026 for Jorge Manrubia’s talk on Lexxy, a new rich text editor for Action Text. Jorge is a Principal Programmer at 37signals, and if you’ve used Active Record Encryption, you’ve used something he built.

Jorge explained why 37signals built a new editor, what Lexxy adds, and how the work opens Action Text to other editors beyond Trix, the editor that’s shipped with Action Text since day one.

In this post, we’ll walk through why Trix became a maintenance burden, why 37signals picked Meta’s Lexical framework over the more obvious open source contenders, and what Lexxy actually does differently inside Action Text.

Read more of Rails World '26: Lexxy for Action Text opens a new window

What Happens to Your Ruby Tools With AI?

When we talk about building with AI, most of the attention goes to what’s new. Models, agent frameworks, protocols, and tools seem to appear every week, making it easy to assume that adopting AI means introducing an entirely new technology stack.

But Rails developers already have many of the building blocks needed to create useful AI-assisted workflows. Generators, Rake tasks, command-line interfaces, schemas, tests, and APIs were designed to make software easier to work with by providing structure and predictable behavior. Those same qualities make them well suited for AI coding tools.

In this context, an AI-assisted workflow doesn’t mean building an agent into a Rails application. It can be as simple as a developer using an AI coding tool to complete a task in an existing codebase, whether that’s adding a feature, running tests, analyzing technical debt, or helping with a Rails upgrade. As these tools become capable of taking more actions on a developer’s behalf, they need reliable ways to interact with the codebase and the tooling around it.

This article explores how existing Ruby and Rails tooling can become part of AI-assisted development, and why introducing AI doesn’t require starting from scratch.

Read more of What Happens to Your Ruby Tools With AI? opens a new window

Herb on Rails

ERB does not know that it is generating HTML. It finds the <% %> tags, evaluates the Ruby inside them, and concatenates everything else as plain text. Whether the result is valid markup has never been its problem.

Herb changes that. On August 25, 2026, the Ruby on Rails core team merged Add Herb as an HTML-aware ERB implementation opens a new window , which brings in Herb opens a new window , an ERB implementation that parses HTML and ERB into a single syntax tree and uses Prism opens a new window for the Ruby inside the tags. Broken markup can now fail while the template compiles, instead of reaching a browser.

In this article, you will learn what Herb is, how to audit your own views with it today, what it can fix for you, what it cannot, and what it costs to run. We used the FastRuby.io views as the test subject.

Read more of Herb on Rails opens a new window

Rails 8.2: The HTTP QUERY Method

RFC 10008, published in June 2026, defines the QUERY method as safe and idempotent like GET, and it carries its query in the request body like POST. Ruby on Rails merged support for QUERY on August 14, 2026, under the 8.2.0 milestone.

I set up a small application on edge Rails to check it working. The routing and the request object are ready, but the parts of the specification that make QUERY more than a POST with better manners are not quite there yet, since Rails parses only JSON bodies and does not enforce the content type rule RFC 10008 requires. In this article, we will check how the QUERY method works in Rails, how to route and test it, how Puma is handling it, and which pieces of the specification are still missing. Everything below reflects the state of things at the beginning of September 2026, and since Rails, Rack, and Puma all have the interesting parts sitting on unreleased branches, it is worth checking the versions yourself before trusting any of it.

Read more of Rails 8.2: The HTTP QUERY Method opens a new window

Irish Chess Union Upgrades to Rails 8.1

Founded in 1912, the Irish Chess Union (ICU) is the governing body for chess across the island of Ireland. It has about 2,500 members and run entirely by volunteers.

Its website, icu.ie opens a new window , has been maintained by webmaster Jonathan O’Connor since 2015. Earlier this year, Jonathan reached out to us. He wanted help taking the ICU’s Rails application from 7.0 to 8.1.

We used Claude Code and our open source Claude Code Rails Upgrade Skill opens a new window to get it done. We also recorded the sessions as a video series, so other teams could see the methodology in practice.

In this article, we’ll walk through the upgrade, one version at a time, and share what Jonathan thought of the process.

Read more of Irish Chess Union Upgrades to Rails 8.1 opens a new window

Upgrading a Deprecated Postgres on Heroku

Heroku sent us an email about the database behind ips.fastruby.io opens a new window , a small app we run for sharing benchmark-ips opens a new window results. That database runs Postgres 15, and the email gave it an end-of-life date on Heroku of January 20, 2027. If we do nothing before December 20, 2026, they will upgrade it to Postgres 18 for us.

Staying in control of when that happens beats finding out on Heroku’s schedule, so I upgraded it that same night. I skipped the method Heroku recommends for a documented one that suited this database better, and still finished the job with commands that are not in their documentation.

In this article, you will learn how we moved a Heroku Postgres database off a deprecated version, why we copied the data into a new database instead of upgrading in place, how much downtime to plan for, and which parts of Heroku’s tooling failed on us. We upgraded from Postgres 15 to 18, but the steps are much the same whichever version you are leaving behind.

Read more of Upgrading a Deprecated Postgres on Heroku opens a new window

The Rails Deprecations You Missed This Summer

Ruby on Rails keeps changing between releases. Five This Week in Rails opens a new window issues rolled in eight Active Record deprecations and behavior changes on Rails main over the last few weeks. Most are small renames. One is a real bug fix that stops a write from leaking outside its association. None of it has shipped in a tagged release yet, main is currently versioned 8.2.0.alpha. Rails has shipped a new minor version roughly every year (8.0 in November 2024, 8.1 in October 2025), so 8.2 landing sometime around the end of 2026 is a reasonable bet, well ahead of binds, which has a committed removal date of 8.3. uniq! is the one to not expect soon: its removal is tied to 9.0, and Rails hasn’t announced a timeline for that one yet. Nothing in your Gemfile breaks today, but you’ll want to know about it before it does. If you’ve been tracking this kind of thing, you might remember we covered deprecated associations in Rails 8.1 opens a new window back in July. This is the next batch.

I’ll get into what’s changing in each of the eight, why the Rails team made the change, and what to update in your own code once it ships. If you want the general playbook for handling deprecation warnings during an upgrade, we have a guide for that too opens a new window .

Read more of The Rails Deprecations You Missed This Summer opens a new window

Turning Audit Findings into CI Checks

You get a site audit report and it looks manageable. A few dozen findings, most of them small: a page with barely any text on it, a link whose text is just “here”, a page whose title tag is a copy of its H1, a hero image heavy enough to hurt the largest contentful paint opens a new window . None of it is that hard. You spend an afternoon on it, close the tickets, and move on.

Then a few months pass, a dozen new pages ship, and the next audit reports the same findings again. Not because anyone ignored the first round, but because the first round fixed pages instead of fixing the process that produces pages.

That happened to us, on this site and on OmbuLabs.ai opens a new window . So the second time around we spent the effort somewhere else. Instead of just fixing the pages, we wrote checks that run on every build and say when a new page has the same problem. It is roughly the same idea as automating a tech debt audit opens a new window : most of the value is not in the report, it is in being able to produce the report again for free. No two of them wanted the same kind of check.

The goal here is search traffic, not a clean report. Thin pages, vague link text, and duplicated title tags are the things that hold a page back in search results, and a page that ships with them costs us traffic until the next audit finds it. A check on every build moves that discovery from months later to the pull request.

In this article, you will learn how we turned three kinds of audit findings into checks that run in CI.

Read more of Turning Audit Findings into CI Checks opens a new window

How to Avoid APM Bill Surprises

You approved an APM tool at a modest monthly rate. A year later, the renewal invoice bears little resemblance to what you signed, and nobody remembers deciding to spend that much more.

APM is worth having when it’s used well: it resolves incidents faster by showing you where in the stack a problem started, it gives you warning before a threshold alert turns into an outage, and it gives you a defensible answer when a client or stakeholder asks whether you hit your SLA (often measured through percentile response times opens a new window like p95 and p99). None of that is in question here. What tends to go unexamined is whether the bill still matches what you’re getting for it.

In this article, we’ll walk through where APM spend typically concentrates, the warning signs that a bill has drifted from usage-driven growth into unmanaged creep, and a concrete checklist for getting ahead of it before your next renewal.

Read more of How to Avoid APM Bill Surprises opens a new window

Repay Tech Debt with the Strangler Fig Pattern

Replacing a business-critical legacy system does not have to mean committing to a risky, all-at-once rewrite. The strangler fig pattern offers a practical alternative: migrate one capability at a time, run the old and new systems side by side, and gradually retire the legacy code as each replacement is validated. This post walks through how it works, where it fits, and a practical Rails-based example of migrating one piece of functionality without stopping the business to do it.

Read more of Repay Tech Debt with the Strangler Fig Pattern opens a new window