Rubyland

news, opinion, tutorials, about ruby, aggregated
Sources About
RubySec 

CVE-2026-12545 (hammer_cli): hammer_cli - Insecure interpolation of the $EDITOR environment variable

A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).
justin․searls․co - Digest 

🎙️ Merge Commits podcast - YAGNI: Retiring from programming

Direct link to podcast audio file

Matt Swanson had me back on YAGNI to talk about the fallout from DHH's Rails World keynote and what it means for your weekend. We discuss what happens to the "one-person framework" when agents write the code, how frustrating it is when something is absolutely correct but still misses the point, and how I've accidentally constructed a dark factory with agents building and maintaining my iOS apps.

We also get into what I'd tell developers who are worried about where all this is heading and why World of Warcraft is my dark horse candidate to beat Grand Theft Auto 6 in November.

Appearing on: YAGNI
Published on: 2026-10-02
Original URL: https://share.tr…

Comments? Questions? Suggestion…

Ruby on Rails: Compress the complexity of modern web apps 

Rails World recordings are online, new minimum Ruby version and more!

Hi, it’s Greg. Let’s explore this week’s changes in the Rails codebase.

The Rails World talk recordings are online
Blazing fast, one week after the event, you can watch all the talks from Rails World on YouTube!

“Autoloading and Reloading” guide community review
The updated “Autoloading and Reloading” guide is ready for community review. Please have a loook and give feedback.

Bump minimum Ruby version to 3.3.5
This commit bumps the minimum Ruby version to 3.3.5 so the WeakKeyMap polyfill can be removed, which would allow using non-Thread/Fiber/etc. as keys, and enable a refactor to prevent iterating over every connection pool.

Remove support for dynamic controller/action in routes
A…

Andy Croll 

Look at all the things he's not doing

There’s a moment in the early seasons of South Park when Cartman et al find the source of an underwear crisis in their mountain town. It’s the underpants gnomes in their cave. They have a plan.

  1. Collect Underpants
  2. ???
  3. Profit

I’ve been considering David’s opening Rails World keynote and realised that this is the main problem I have with it. Rails World is about “shaping the future of Ruby on Rails”. Instead what we got was opinionmaxxing: a lot of certainty about the destination, but in his own words, not much that was ‘practical’ or ‘prescriptive’ about getting there.

  1. The model got good at writing code
  2. ???
  3. Models write all code, we don’t need to care

There’s a vibration…

RoboRuby 

Ruby AI News - October 2nd, 2026

.bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; } .bh__table_cell { padding: 5px; background-color: #FFFFFF; } .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; } .bh__table_header { padding: 5px; background-color:#F1F1F1; } .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }

Welcome to the 38th edition of Ruby AI News! This edition features… well you know what we’re talking about this edition. This is a special edition, the 39th edition will follow next week.

Read on the web

Here We Go

There are…

Writing | Aaron Allen 

Hanami, Why?: Bits & Bobs

Welcome back to my "Hanami, Why?" series. If you missed it, be sure to read Hanami, Why?: Introductions before you start this issue. It is my intent to keep these issues focused on singular subjects whenever possible. However, in today's issue we are going to cover several topics that are too small to warrant their own issue but still important to have for context. As I mentioned, Hanami has a lot of important abstractions, and today we are going to be covering what I consider "system level" abstractions. We have lots to cover, but this context will be important for a further understanding of how Hanami works.

Dependency Injection

Most of the time Ruby is pretty great at telling you what a…

Remote Ruby 

Live At Rust, Uhh, Rails World 2026

Recorded live from Rails World 2026, Andrew, Chris, David, Jason Charnes, and eventually Andy Croll, unpack the strange mood surrounding this year’s conference. Much of the conversation centers on DHH’s keynote and the increasingly agent-driven future of software development: if AI can write, debug, and even understand the code for us, what happens to the value of frameworks, developer expertise, documentation, and even Ruby itself? They also dig into Hotwire, Active Search, Herb, Active Job Continuations, security concerns around AI-generated software, and what the Ruby community might rally around if the language becomes less central to how developers identify themselves. And because it’s…

37signals Dev 

Warming up the Puma master before it forks

Basecamp 5 runs on Puma in cluster mode: one master process with preload_app! and 63 single-threaded workers per host, deployed as a Docker container with Kamal.

We serve Basecamp from several sites. Each site has its own web hosts and a read replica of the database, and writes go to a single primary database in one of them.

On our busiest hosts, each deploy left up to 2,000 requests waiting while the new workers warmed up. We reduced those queues by running signed-in requests through the app in the Puma master, before it forked the workers.

Why 63 single-threaded workers?

Basecamp has always served web requests from processes rather than threads. It ran on Unicorn, which only does…

Giant Robots Smashing Into Other Giant Robots 

NWRUG's (Manchester, UK) October 2026 meeting — It's time to bin your VCR

The next North West Ruby User Group in Manchester, UK is in a fortnight on 15 October at Colony, One Silk Street. Rob Whittaker will take us through one of his hot-takes: VCR does more damage than good, and there are imperfectly better ways to stub your external requests.

Rob Whittaker is Director of Software Development at thoughtbot. He has over two decades of professional web development experience and has worked with Ruby and Rails since 2012. (He’s also the co-organizer of NWRUG!)

We’ll be at the venue for pizza from 6:30pm with the talk starting at 7pm. Afterwards we’ll retire to The Crown & Kettle for a drink. The venue, pizza, and drinks are kindly provided by NWRUG’s sponsors Fat…

Awesome Ruby Newsletter 

💎 Issue 541 - What About Rails?

Shopify Engineering 

ShopGym: Realistic, reproducible sandboxes for shopping agents

ShopGym creates realistic online stores and generates shopping tasks based on each store’s products and features. Developers can then repeatedly test shopping agents under consistent conditions.
John Nunemaker 

YAGNI: Camping Chair Development

I joined Matt Swanson on YAGNI to talk about how I build software now across Fireside, Flipper, and Box Out. Some of it even happens from a camping chair.

Some of the highlights:

I’m Not a Craftsman. I always thought of myself as a craftsman. Bespoke furniture. Samurai. Honor. All that. Then on December 14th I turned on a 20x Claude plan just to try Opus and realized nope, I just love shipping stuff and solving problems. These days I read the data models and the queries because those affect how fast things are for customers. JavaScript and view code? I don’t read it. Does it look right? Is it responsive? What’s my Lighthouse score? Good enough.

Stripping Back. I went through a phase of…

John Nunemaker 

The Friday Deploy: Changing the Wheels While the Car Is Moving

Garrett and I started a podcast. It’s called The Friday Deploy, and the tagline is the whole point: ship on Friday, sleep through the night.

We already do a marketing and business podcast for Fireside, so we figured, let’s go full on dev with this one. Feature flags, deployments, infrastructure, incidents, product decisions, and all the little practices that let you deploy whenever you want without the sweaty armpits. Sometimes it’ll be just me and Garrett, and sometimes we’ll bring on a guest to walk through what they do.

Subscribe on Apple Podcasts, Spotify, or RSS.

Episode 1: Changing the Wheels While the Car Is Moving

We’re almost exactly two years into owning Fireside, so for the…

Ruby on Rails: Compress the complexity of modern web apps 

Rails World 2026 recap: All talks online

Happy to report that in record time, all Rails World 2026 talks are now online.

Find the full playlist here.

While all four keynotes got everyone talking about AI, this year’s talks covered a good balance of what’s new in Rails and how Rails developers are using AI.

The AI-focused talks covered: making codebases agent-friendly, harness engineering, generators, AI pipelines in plain Ruby, agent loops driving Ractor-safety, building MCPs, and rapid deploys with the help of agents.

There were also talks about: Lexxy, Active Search, ONCE, Herb in Rails 8.2 and durable Active Job workflows, plus deep dives into Solid Cable, Hotwire, Kamal, sharding, the RubyGems compact index, and HotCell…

OmbuLabs.ai 

Automating Repetitive Work with Skills and MCP

Every month, someone on our team was doing the same thing: pulling data from a handful of systems, assembling it into a document, and writing up a summary before it could go to the client. The work was not complicated. It was just slow, repetitive, and easy to get wrong.

That monthly report was not an isolated case. We’ve built a few internal tools around the same pattern: a repetitive workflow, data sitting in one or more external systems, and a human who needs to stay in the loop at the right moments. Each time we reach for a solution, we face the same question: how much infrastructure does this actually need?

In this post, we will look at the characteristics of a workflow that fit this…

Alchemists: Articles 

Joy of the Craft

Cover
Joy of the Craft

This collective was founded on a simple idea that you should enjoy the work you do including a strong sense of purpose in order to enrich the lives of your team and customers combined. Profit, while important to keep the lights on, is not the driving force. Building expertise and using software to make life more enjoyable for folks is much more rewarding. Plus, it feels good to wake up each morning knowing you are working in a code base that is well maintained, always up-to-date, a joy to use, and a benefit to society.

The Engineer’s Oath helps us never lose sight of our purpose while our Engineer’s Rigor keeps us honest because you can’t make an impact in life if…

Ruby Weekly 

Rails' next rich text editor hits 1.0

#​819 — October 1, 2026

Read on the Web

Ruby Weekly

Lexxy 1.0: Rails' New Rich Text Editor to Replace Trix — Built on Lexical and already powering 37signals' Basecamp 5, it gives you tables, Markdown shortcuts, smart links, syntax-highlighted code and mentions, and it's easy to swap into Action Text in place of Trix.

Jorge Manrubia (37signals)

💡 The Lexxy site has a sandbox demo if you'd like to try it out first.

Switching APM? One Ruby Gem Now Covers Distributed Tracing — Errors, N+1s, Sidekiq jobs, logs, host metrics and now distributed tracing (beta) in one Ruby gem. Every feature on every plan, unlimited…

RailsCarma – Ruby on Rails Development Company specializing in Offshore Development 

Top 10 Mobile App Development Companies in USA 2026

he demand for mobile applications in the United States continues to expand as businesses use apps to deliver digital products, improve customer experiences, streamline operations, and create new revenue channels. For companies planning a new mobile product in 2026, choosing the right mobile app development company in the USA involves more than comparing development prices. Technical expertise, product strategy, UX design, security, scalability, post-launch support, and experience with emerging technologies all matter.

The U.S. digital environment provides a strong foundation for mobile-first products. DataReportal’s 2026 U.S. report records 324…

Rails Designer Blog 

More than click and submit: use any event with Stimulus

I recently surprised someone by showing you can use any event besides the common click, submit and keydown events. The Stimulus docs list those seven default events and their shorthand equivalents. Enough for most cases. But the data-action descriptor is event->controller#method where you can bind to anything the DOM throws at you: native element events, global document events, even custom dispatched events. All work the same way.

I put together a small demo repo to show a handful of these in action. Lets go over them and maybe you find a way to refactor and simplify one of your Stimulus controllers.

First a few you probably have used before. A <textarea> fires input on every keystroke. The …

Planet Argon Blog 

Upgrading a Next.js App Before Anything Breaks

Upgrading a Next.js App Before Anything Breaks

Make the case for a big migration, keep it reviewable, and ship it on a live site without pausing everyday work.

Continue Reading

Evil Martians 

SF Ruby Conference: regular ticket prices end September 30

Authors: Camila Mirabal, Tech writer, and Travis Turner, Tech EditorTopics: Developer Community, Rails, AI

Regular SF Ruby Conference tickets are $450 through September 30. Meet Ruby friends, play The Pier, join small-group conversations, and explore the 2026 program in San Francisco.

Not a single person in the Ruby community has told us they go to conferences for anything other than meeting new people and catching up with old friends. Our community needs that shared warmth and joy more than ever.

But going to a conference alone can be intimidating. You walk into a room full of people you don't know, have no idea whom to talk to, and end up checking your phone between talks. We've all been…

The Rails Tech Debt Blog 

Rails World ‘26: The RubyGems Compact Index

I was in the audience at Rails World 2026 for Jenny Shen’s talk on the RubyGems Compact Index, the last technical talk before the closing keynote. Jenny is a Senior Developer at Shopify and a RubyGems.org maintainer, and she opened by asking the room who had heard of the compact index before. Not many hands went up, which was kind of the point: it’s a piece of infrastructure that handles tens of millions of requests a day, and most Rubyists never think about it.

Jenny Shen presenting on stage at Rails World 2026, in front of a large screen showing the glowing 'Rails World' logo

Every time Bundler resolves your Gemfile, it’s talking to the compact index. In this post, we’ll walk through what the compact index actually is, how RubyGems.org keeps it in sync at scale, and two features Jenny helped ship in…

Writing | Aaron Allen 

Hanami, Why?: Introductions

I mentioned in my Hello, world! post that I built this site using Hanami. This site may seem simple on the surface; it is, after all, just a blog. However, the backend is packed with features that help me day to day. I have built a tool that lets me cross-post to both Bluesky and Mastodon. I have a private journal where I can keep notes throughout the day. There is a custom analytics engine to provide me with insights on how well my blog posts are doing. There is a messaging backend that lets readers reach me through my contact form without cluttering my inbox. I have also built a task manager that syncs with both Linear and GitHub Issues and helps me track what I need to do. Most…

The Ruby on Rails Podcast 

Episode 554: The future of Rails with Obie Fernandez

What does the future of Ruby and Rails look like as AI begins to fundamentally change how software gets built?

Recorded at Rails World, David sits down with longtime Rails community member Obie Fernandez to talk about the rapid rise of agentic development and what it means for programmers, teams, and the craft of software engineering. Obie argues that while AI can dramatically accelerate development, the industry is still figuring out how to apply the discipline, constraints, and guardrails necessary to use these tools effectively in production systems.

The conversation explores how software development may be moving to a new level of abstraction—away from carefully crafting…

Josh Software 

Inside the Go Compiler: Optimizations That Make Your Code Faster

Most Go developers know how to write efficient Go code. But very few know what happens to that code after go build. Consider: How many function calls happen here? The obvious answer is one. But the real answer may be zero. The Go compiler can inline add, turning the call conceptually into: It can then … Continue reading Inside the Go Compiler: Optimizations That Make Your Code Faster
RailsCarma – Ruby on Rails Development Company specializing in Offshore Development 

Machine Learning Basics: An Enterprise-Friendly Guide 2026

Machine learning (ML) has moved beyond being an experimental technology reserved for data science teams. In 2026, enterprises are using machine learning to forecast demand, detect fraud, personalise customer experiences, automate decisions, optimise operations, identify risks and turn large volumes of business data into actionable insights.

For organisations evaluating AI adoption, however, machine learning is not simply about choosing an algorithm and training it on historical data. Successful enterprise ML requires a combination of business strategy, quality data, suitable models, reliable software engineering, cloud infrastructure,…

This enterprise-friendly guide explains the machine…

RubyGems Blog 

4.0.22 Released

RubyGems 4.0.22 includes enhancements and bug fixes and Bundler 4.0.22 includes enhancements, bug fixes and documentation.

To update to the latest RubyGems you can run:

gem update --system [--pre]

To update to the latest Bundler you can run:

gem install bundler [--pre]
bundle update --bundler=4.0.22

RubyGems Release Notes

Enhancements:

  • Add –source option to gem exec command. Pull request #9765 by Akshay Birajdar
  • Keep credentials on redirects only within the same origin. Pull request #9909 by Hiroshi SHIBATA
  • Validate the version field in Gem::Installer#verify_spec. Pull request #9890 by Hiroshi SHIBATA
  • Installs bundler 4.0.22 as a default gem.

Bug fixes:

  • Remove the…
Sam Ruby 

Rust is the answer to the wrong question

The below was 100% written by a human. TL;DR: porting an app to another language is merely an anecdote. One shoting an application from scratch optimizes the easy part (initial authoring) and completely misses the point on the hard part: maintenance. Repeated one-shots are not the answer to security vulnerabilities. What's needed is a rock-solid contract layer, complete with escape hatches to cover what the DSL doesn't handle natively. And a compiler. Prologue A chess program can beat me. That isn't clearing a high bar - I'm mediocre at chess. The fact that a LLM can beat me at coding isn't surprising either, despite the fact that I can credibly claim to be a world class coder, and have a…
Sam Ruby 

Nokogiri, Loofah and Crass, Compiled

I built these for Roundhouse, which compiles Rails applications, and Campfire needs all three: Action Text sanitizes every message through rails-html-sanitizer, which is built on Loofah, which is built on Nokogiri and Crass. But none of them need Rails, and I suspect they are more useful on their own than inside a compiled Rails app. What they are spinel-nokogiri parses HTML5 (with gumbo), HTML4 and XML over the same libxml2, with the same patches, that Nokogiri ships. It supports CSS and XPath queries, editing and serialization. spinel-loofah is Loofah's HTML sanitizer: its safe lists, its built-in scrubbers (:strip, :prune, :escape, :whitewash, :nofollow, …), custom scrubbers, and…
The Rails Tech Debt Blog 

Rails World ‘26: Herb and ReActionView

I watched Marco Roth’s talk at Rails World 2026, and it left me excited about where the Rails view layer is headed.

Marco has spent the last couple of years building Herb, an HTML-aware ERB parser that is on its way into Rails 8.2 core, and at Rails World he showed what he is building on top of it: A project called ReActionView.

Marco Roth presenting on stage at Rails World 2026, in front of a large screen showing the glowing 'Rails World' logo

ReActionView adds real reactivity to your existing .html.erb templates, no Hotwire, no Stimulus, no JavaScript you have to write yourself. That is the part that got me.

Hotwire already does a lot for us, but it still asks you to write a Stimulus controller once the interaction gets specific, and Marco’s demo showed a page that updates itself because the…

The Rails Tech Debt Blog 

Run the Rails Agent Benchmark Yourself

Last month the Rails Foundation published something the Ruby on Rails community had not seen before: a leaderboard of coding agents scored on real Rails work. The first Agents on Rails report topped out at 92% in the Accuracy column for the best model tested, which is roughly what you would expect from a field of frontier models. The Rails API recall column tells a different story: it shows the share of runs where the model reached for the Rails API that a task was built around, instead of hand-rolling its own version. In that first report it ran from 8% to 35%, and a follow-up published on September 2 moved the top of the range to 41%.

Those results describe Writebook, the application the…

code.dblock.org | tech blog 

zBalls: a 1998 Java Applet

In January 1998, a classmate and I wrote a game. It was called “Bolongas zBalls”, and it was a Java applet.

You click to start, then move the mouse, without clicking. Touch the dark ball to blow it up, and the next ball turns dark. Clear them all and the next level doubles the number of balls. Touch a plain ball and it spawns another one, so if you’re sloppy, the balls multiply until you lose. Each level has a time limit.

The intro music is the theme song from Capitaine Flam, the French version of the Japanese cartoon Captain Future, which aired on TF1 in 1981. I honestly don’t remember why we used it, nor why the game is called “Bolongas”.

Applets were removed in JDK 26, which is…

code.dblock.org | tech blog 

Good Morning, Dave: the 1998 INET Conference Kiosk Launcher

In July 1998, the Internet Society held INET ‘98, “The Internet Summit”, at Palexpo in Geneva. The University of Geneva provided about 250 computers for the conference, and I was a student there. I wrote much of the conference network’s website, www.inet98.ch, and the launcher that ran on the public Windows 95 PCs instead of Explorer.

The INET '98 network website

The Inet 98 Launcher running under Wine on macOS

The Inet 98 Launcher was a full-height bar on the left of the screen with a button for each installed application: Internet Explorer, Netscape, PC Pine, Telnet, WS-FTP and Office 95 and 97. I wrote it in Delphi 3. It showed a screen saver when a machine sat idle, reset itself, and could reboot the PC to return it to a clean state.

It also had a…

The Bike Shed 

508: The Wonders of Static Analysis

In this week’s episode of The Bike Shed, Aji and Joël dive into the distrust around the phrase ‘programmer discipline’, why you cannot just rely on willpower, and how Static Analysis tools can help with not crossing boundaries.

From competing priorities and team member changeovers to documentation not being read, things can still fall through the cracks, so having a tool that can check the ones and zeroes that you send into GitHub. So what makes Static Analysis so different to other forms of analysis? Well, you’ll have to listen to the episode to find out!

—

Mentioned in this episode:
Joel’s talk at Rails World - ‘Harness Engineering on Rails’
Justin Searle’s Standard.rb talk - …

Hanakai 

Welcome, thoughtbot!

I’m so happy to share that thoughtbot is our newest silver sponsor!

thoughtbot logo

If you’ve written Ruby for any length of time, thoughtbot has most likely helped you out. Maybe it was a blog post, an episode of The Bike Shed, one of their many open source gems, or one of the lovely humans who work there. They’ve given our community so much for so long.

Now they’re backing Hanakai too. Here’s Rob Whittaker, their director of Software Development based in the UK, on why:

thoughtbot has built web apps and open-source Ruby libraries for over 20 years. We know how much any framework depends on the people who maintain it. Ruby is stronger with a diversity of thoughts, opinions, and approaches. The…

Jardo.dev: Blog 

Hardly Promethean

Last week I published What About Rails, a dive into DHH's Rails World keynote. Smarter people than me had interesting things to say about it:

You have the most powerful tool you ever had, you have become a 1000x maker, and you can't think of how to make your stack 10x better?

José Valim poses an excellent question. I tried to find an answer.

The Bottleneck Isn't Gone

They're not gonna be web apps much longer. They're gonna be native applications, because the price of developing those things has gone to damn near zero.

The move to native apps for the frontend and Rust on the backend isn't about any particular technology. It's about cost. DHH isn't the first to make this case.

Back…

The Rails Tech Debt Blog 

Rails World ‘26: Lexxy for Action Text

I was in the audience at Rails World 2026 for Jorge Manrubia’s talk on Lexxy, a new rich text editor for Action Text. Jorge is a Principal Programmer at 37signals, and if you’ve used Active Record Encryption, you’ve used something he built.

Jorge explained why 37signals built a new editor, what Lexxy adds, and how the work opens Action Text to other editors beyond Trix, the editor that’s shipped with Action Text since day one.

In this post, we’ll walk through why Trix became a maintenance burden, why 37signals picked Meta’s Lexical framework over the more obvious open source contenders, and what Lexxy actually does differently inside Action Text.

The Problem

Trix is built on contented…

Remote Ruby 

Rails at Scale, Roundhouse Performance, and AI-Era Supply Chain Security

Andrew and Chris are back with a packed episode covering everything from Rails World anticipation and Rails 8.2 to security, Ractors, AI-assisted development, and some ambitious new Ruby tooling. They dig into RubyGems recent spam-publishing incident and Trusted Publishing, look at Shopify’s push toward Ractor-safe Rails, and explore Roundhouse, a project experimenting with compiling Rails applications into entirely different target languages. They also talk about using Claude for project planning and open source maintenance, new approaches to AI beyond traditional LLMs, the surprisingly inexpensive architecture behind Turbopuffer, PlanetScale’s new TIN search extension, and Andrew’s move…

Aha! Engineering Blog 

Coding AI without deterministic outcomes

I recently had a conversation with an engineer on our team about working with AI. He was frustrated with some of the work he had been doing on AI features, and a lot of what he was saying resonated with me. He was putting into words things that I ha
Sam Ruby 

As If

Yesterday, in Partly in the Right, I asked where the information comes from when an agent produces a result, and what checks it. Today I have a sharper version of that question, and a new piece of evidence to ask it about.

The as-if rule

Aaron Patterson's closing keynote at Rails World was about optimization, and he framed it with a rule language implementers know well. The C++ standard puts it in a footnote: an implementation "is free to disregard any requirement of this International Standard as long as the result is as if the requirement had been obeyed, as far as can be determined from the observable behavior of the program." C has the same idea without the name. The standard describes…

code.dblock.org | tech blog 

The Second Life of Autoconf for MS-DOS

Before GNU Autoconf generated configure scripts, there was a DOS program called Autoconf. It let you keep one CONFIG.SYS and one AUTOEXEC.BAT, then choose among boot configurations by pressing a key.

You did not have to wait for a menu. The PC BIOS kept early keystrokes in its keyboard queue, so you could press a configuration letter before AUTOCONF.SYS had even loaded. When the driver finally ran, it found the key and continued immediately.

I did not write the original. I copied its x86 assembly source by hand from a French computer magazine. It was the first assembly program I had ever seen and the first piece of code I compiled. I spent the next three or four years extending it into my…

Tim Riley 

Continuations 2026/39: Syntactical possibilities

  • This was a good week for progress on our code!

  • A couple of tests started flaking on JRuby mid-week. I like to get on top of these pretty quickly, so I pushed up fixes to dry-monads and dry-effects. Now that we’ve achived full JRuby support across Dry, I’m very serious about making sure we keep it!

  • Adam has been on a tear lately. This week he added % formatting support to the new Dry::CLI::Style::Text, and prepared a built-in spinner for Dry CLI! 

  • I merged a fix to make provider usage work inside Hanami slice class bodies, and thereby restored single-file Hanami apps. Now we have a test for it, which will help ensure we don’t accidentally lose the capability again.

  • A few weeks ago Aaron…

37signals Dev 

Lexxy 1.0 is here

Today we are releasing the version 1.0 of Lexxy. Lexxy is a rich text editor for Rails built on Lexical. It already powers Basecamp, Fizzy and many others, and it will become the default editor in Rails. I recently presented it in Rails World (slides, video coming soon). This is the article version of my talk.

Trix hit a wall

Trix has been our editor since 2015, and every Rails app’s editor since Action Text shipped in Rails 6. It’s small and reliable, and it has served millions of people for a decade. But in the last few years our customers kept asking for features like tables or code highlighting, and we kept struggling to deliver them. The reason is the Trix document model.

A Trix…

Sam Ruby 

Partly in the Right

I'm speaking at Deccan Queen on Rails in Pune, October 8–11. In The Hidden 4GL I described what I planned to bring, and two days ago, in Pencils Down, Notation Up, I responded to the Rails World keynote. I'm still refining the talk, and still watching for signal. This post is what I've found worth examining since. None of it settles anything. I've been reading other people's accounts of what agents can and can't do, and I've noticed something: they contradict each other, and I believe every one of them. There's an old parable about this. Six blind men meet an elephant. One touches its side and says it is a wall; one touches the trunk and says it is a snake; one the tusk, a spear; one the…
Noteflakes 

On Kids and Football

My father was born and raised in a village called Moldovița, nestled at the feet of the densely forested Carpathian mountains in Romania. One of my favorite tales he used to tell us about his childhood is about the Jewish kids’ football team Maccabi Moldovița. All of the boys dreamed about playing in a football team, but they didn’t even have a real ball. This didn’t stop them though, and they came up with a plan: the Schmoll shoe paste company had a sales promotion: collect 100 shoe paste caps, send them to the factory, and you’ll get a free football! The kids did their best to waste as much shoe paste as they could, which of course led to the indignation of their parents, but finally…

Writing | Aaron Allen 

Hello, world!

Hello, and welcome to my new website! My name is Aaron and I have been writing software since I was thirteen years old (twenty-seven years ago). I am a senior software engineer at Credit Ninja and have worked for companies like Root Insurance and Zillow. The main focus throughout my career has been backend web development using my primary love language, Ruby. In my spare time, I contribute to the Hanakai organization, working on Hanami, dry-rb, and ROM. Over the last few years, I have also begun to fall in love with Rust and have published a handful of projects. I am from and live in San Antonio, Texas. I have four kids ranging in age from seven to twenty-two.

This will be the fourth(?)…

Julia Evans 

Replacing the old battery on rechargeable bike lights

Hello! Recently I needed bike lights for my bike. And I remembered that I already had rechargeable bike lights that I bought ten years ago, that I hadn’t tried in a long time. I tried to recharge them, but after fully charging them, they only worked for maybe 5 minutes before they turned off again.

I don’t know much about electronics, but I’ve been curious about whether it’s possible to fix old electronics for a long time, and this seemed like the perfect repair project because I might just need to replace the battery.

So I went to the local queer makerspace where I’m a member to use the soldering iron and try to do it! I don’t know much about electronics and this post does not contain any…

Hi, we're Arkency 

6 levels of knowledge management maturity in organizations

6 levels of knowledge management maturity in organizations

“Zapomniałem” is Polish for “I forgot”.

On Arkency’s Slack, our main communication channel, it has been used over 1200 times.
And I truly believe I work with exceptionally organized and meticulous people.

That only confirms what I wrote in my previous post: organizations are surprisingly good at forgetting.

That post described how we maintain an organizational knowledge graph with an LLM and event sourcing.
It was about the destination.
This one is about the road that led us there.

Looking back at how we handle knowledge at Arkency, I identified 6 levels of maturity.
I presented them yesterday at Programistok in Białystok,…

RubySec 

GHSA-6wmv-xq9m-fmp7 (dalli): Memcached command injection through numeric arguments to incr/decr and fetch_with_lock

Dalli's meta protocol request formatter wrote some numeric arguments into memcached commands without converting them to integers. If an application passes an attacker-controlled String to one of these arguments, CRLF sequences in it are sent to memcached as additional commands on the same connection, letting the attacker run arbitrary memcached commands, such as overwriting keys or running `flush_all`. The affected arguments are the `default` (initial value) argument of `Dalli::Client#incr` and `#decr`, and the `lock_ttl` and `recache_threshold` arguments of `Dalli::Client#fetch_with_lock` (4.2.0 and later). In 3.2.x and 4.x, only clients created with `protocol: :meta` are affected; the…
RubySec 

GHSA-42qh-8mx8-7wqm (rack-proxy): HTTP response smuggling via ambiguous backend response framing in rack-proxy 1.x

## Summary rack-proxy 1.0.0 through 1.0.2 can forward an incorrect Content-Length when a backend response contains both Transfer-Encoding and Content-Length. Net::HTTP removes chunked framing from the body, while rack-proxy strips Transfer-Encoding but retains the backend-supplied Content-Length. This affects both the default streaming mode and streaming: false. ## Impact and Preconditions A malicious, compromised, or attacker-influenced backend can supply a length shorter than the dechunked body. When a frontend Rack handler trusts this length and uses persistent connections, surplus bytes can be interpreted as a subsequent HTTP response, allowing response-queue poisoning and…
Rails Revelry 

The Job Was Enqueued by Older Code

What happens to the jobs already in the queue when I rename their class?

The code change looks straightforward: rename the file, update the callers, and fix the tests.

But a job enqueued before the deploy might wait hours or days before a worker picks it up. By then, the old class is gone.

I wanted to follow that job through the rename and work out what the new release still needs to support. Keeping the old class around seems reasonable, but then we need to decide when we can remove it.

Let’s start by removing it.

Suppose we rename FulfillOrderJob to DispatchOrderJob, update every call site, and deploy. New requests now enqueue DispatchOrderJob. A job scheduled by the previous release still…

MadBomber Software 

Introducing Asgard: a Thor-Based Task Runner

Introducing Asgard: a Thor-based task runner where tasks live in .loki files

Asgard 0.4.0 was released on September 26, 2026. It is a Ruby task runner: define tasks as methods in a .loki file, declare what each task depends on, and run them with asgard <task>. The command line is handled by Thor, so subcommands, typed options, argument validation, and generated help are all available without extra code.

The part I’d point to first is how dependencies are declared. One depends_on line says which prerequisites run one after another, which run at the same time, and in what order those groups happen. Serial, concurrent, or a mix of both, all in the same line, with no separate job-count flag…

MadBomber Software 

Pencils Down: My Take on DHH’s Rails World 2026 Keynote

Pencils Down: My Take on DHH’s Rails World 2026 Keynote

This week David Heinemeier Hansson opened Rails World 2026 in Austin, Texas, with a keynote that has had the Ruby community talking ever since. A few days later Matt Solt asked me, “By the way, I’m curious to know your thoughts on David’s keynote.”

I watched it. I agree with him 100%.

My reply to Matt ran longer than he probably expected, and it turned into this post.

What David said

If you haven’t seen it, the opening keynote is on YouTube. The short version: hand-writing code is no longer an economically viable skill for most programmers at most companies. He didn’t pitch that as doom. He pitched it as an inflection point.

He…

RoboRuby 

RubyRoles: match with Ruby opportunities around the world

.bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; } .bh__table_cell { padding: 5px; background-color: #FFFFFF; } .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; } .bh__table_header { padding: 5px; background-color:#F1F1F1; } .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }

Thanks to SerpApi, the world’s leading API provider of search data, for sponsoring this post and the new RubyRoles site. Be sure to check out their careers page as well, they’re hiring!

Read on the web

Introducing RubyRoles

Sam Ruby 

Pencils Down, Notation Up

I watched the opening keynote at Rails World 2026 expecting a talk on "Shaping the Future of Ruby on Rails." What I found instead was important and needed to be said, but it wasn't quite what that slot on the agenda had led me to expect. The message I heard was that LLMs are a game changer (I agree), and that we are at an exciting point in history (again, agreed). The keynote closed with: So take the white pill, take the optimism pill, lean in. [...] realize there is only one choice, and that is for you to embrace the future with optimism, with gusto, with full acceleration. The black pill is for fucking losers. Don't be a loser. There is only one choice, he said. I'd like to argue…
Ruby on Rails: Compress the complexity of modern web apps 

See you in Lisbon!

Hi, it’s Claudio Baccigalupo with your updates on the Rails codebase.

What a week! Rails World took over Austin with more than a thousand attendees from all over the world. I was able to meet my fellow newsletter editors and to thank the amazing Amanda Perino for another successful conference.

This Week in Rails + Amanda Perino

And now… let’s see what changed on main in the last seven days.

Newly released: Rails 8.1.4 and 7.2.4
Take a look at their CHANGELOG (v8.1.4 and v7.2.4) for all the new features.

The Asset Pipeline Guide rewritten
Now with a bigger focus on how a developer would use the asset pipeline and Propshaft: check it out. Then go read the Active Record composite primary keys guide which has also been imp…

New framework default to…

Weelkly Article – Linking Ruby knowledge from the most remote places in the world. 

Going Deeper into Ruby with Polished Ruby Programming, Second Edition

Going Deeper into Ruby with Polished Ruby Programming, Second Edition September 25, 2026 I recently had the opportunity to review Polished Ruby Programming, Second Edition by Jeremy Evans, and the timing was particularly interesting for me. Over the last few months, I have been spending more time going deeper into Ruby and Ruby on Rails, … Continue reading Going Deeper into Ruby with Polished Ruby Programming, Second Edition →

Jardo.dev: Blog 

What About Rails?

David Heinemeier Hansson is, for better or worse, still in charge of Ruby on Rails. I'd love to stop paying attention to him, but I build applications with Rails, so his actions affect me and my clients. Yesterday, he gave the opening keynote at Rails World 2026, where he laid out his vision for the future of Rails.

Or that's what his talk should have done. His keynote had very little to do with Rails. Here's what he did talk about, and what it means for Rails.

The Gist of It

I have retired from being a professional programmer.

Yes, he said that. No, that doesn't mean he's stepping away from software development. He now styles himself a "maker." He now claims that English is the best…

Awesome Ruby Newsletter 

💎 Issue 540 - Show HN: Radius – A Meetup.com Alternative

Schneems - Programming Practices, Performance, and Pedantry 

A Type Stronger than the Sum of its Components

Have you ever written a type that you appreciated so much you still think about it? Like eating a really good meal, where if you try hard enough, you can still recall the taste in your mouth. I had a mini moment of Rust joy the other day and wanted to share the experience.

TLDR: I turned an enum with N variants into N types. Nothing earth-shattering, but it made my life better.

Specifically, std::path::Component is an enum that you can get from any std::path::Path reference. Where a path can be viewed as an iterator of components. To give you an example /tmp/hello is [Component::RootDir, Component::Normal("tmp"), Component::Normal("hello")]. This enum is very handy for…

Ruby on Rails: Compress the complexity of modern web apps 

Rails Version 7.2.4 has been released!

Hi everyone,

I am happy to announce that Rails 7.2.4 has been released.

As stated in the maintenance policy, this is the last release of the 7.2.x series.

Security issues and bug fixes will only be provided for the 8.0.x and 8.1.x series.

CHANGES since 7.2.3

To see a summary of changes, please read the release on GitHub:

7.2.4 CHANGELOG To view the changes for each gem, please read the changelogs on GitHub:

Full listing

To see the full list of changes, check out all the commits on GitHub.

SHA-256

If you’d like to verify that your gem is the same as the one I’ve uploaded, please use these SHA-256 hashes.

Here are the…

Ruby Weekly 

What if your Rails app didn't need Rails?

#​818 — September 24, 2026

Read on the Web

🤔 DHH opened Rails World yesterday with a keynote that may have implications for Rubyists. I know readers like and loathe DHH in equal measure, so my writeup is at the end of this issue to either read or skip as you prefer.

Ruby Weekly

Benchmarking Compiled-Away Rails on Three Rubies — Roundhouse can compile (some!) Rails apps to simpler Spinel-compatible Ruby. But how does "Rails-free" Ruby fare on CRuby, JRuby and TruffleRuby? In Sam's tests, 3-17x faster than Rails, though TruffleRuby, the fastest at running stock Rails, gains least.

Sam Ruby

💡 Want to try for yourself? Rou…

OmbuLabs.ai 

What Jev Is (and Isn’t): A Model for Decisions

On September 15, 2026, TypeSafe announced Jev, the first of what they call System One models. The launch came with a very low price, a lot of speed claims, and the promise that it “can’t hallucinate”. The obvious first question is whether this is just another Large Language Model (LLM) with a smaller bill.

It isn’t, and the reason is more interesting than the price. In this article, we’ll look at what Jev actually is, what it isn’t, and why that difference matters when you decide where AI belongs in your software.

A quick note on where this comes from: Jev launched in early access. This post is based on a careful reading of TypeSafe’s announcement and documentation, and I’ll point out the…

Ruby on Rails: Compress the complexity of modern web apps 

Rails Version 8.1.4 has been released!

Hi everyone,

I am happy to announce that Rails 8.1.4 has been released.

CHANGES since 8.1.3

To see a summary of changes, please read the release on GitHub:

8.1.4 CHANGELOG To view the changes for each gem, please read the changelogs on GitHub:

Full listing

To see the full list of changes, check out all the commits on GitHub.

SHA-256

If you’d like to verify that your gem is the same as…

code.dblock.org | tech blog 

Porting a 1996 Pascal/Delphi Calculator to Rust (CLI + MCP)

In his Rails World 2026 keynote DHH talks about one-shot apps built almost instantly with an agent as part of Omarchy. His canonical example is Omacalc, a dead simple calculator. It’s a good demo and not a hard problem. Let’s take it further and rewrite a more advanced calculator in Rust that we can also run as an MCP server, so an AI coding agent can outsource arithmetic to it instead of hallucinating a square root.

In 1994 I wrote an expression evaluator for a lab assignment. It grew into Expression Calculator, a shareware Windows app I sold through a company I co-founded, Vestris Inc. In 1997 it got pressed onto a CD-ROM and sold 3,000 copies in Germany under the name Global Calculator.…

Rails Designer Blog 

Lazy loading, optimistic UI and more in Rails with Attractive.js

This is the last article of a series where I introduce Attractive.js 1.0.0 (in pre-release now).

In this last article I want to highlight how Attractive can be a nice addition and in some cases a complete replacement for Hotwire.

I created a simple message board in Rails. No Stimulus anywhere, nor Turbo Streams. Check it out!

rails-attractive-demo.jpg

Most of the features of the is build one Attractive extension I intentionaly left out last week; Attract. It serves two purposes:

  • intercept form request and send fetch instead (we know that technique!), and:
  • work with attract JSON…

One partial, three…

code.dblock.org | tech blog 

Using AI Effectively in Technical Writing

I write a lot, and I use AI a lot. But AI does not write my blog posts. Mostly.

AI is useful for making some of my writing less tedious. Recently, I asked GitHub Copilot CLI to read a few dozen posts from this blog and derive a VOICE.md to assist my writing. The result is now checked into this repo and linked from AGENTS.md, so any AI agent working here gets the same reminder: this blog is authored by me, not by AI and the agent’s job is to help me rather than pretend to be me.

The useful and interesting part of VOICE.md was how it captured my weirdly specific patterns.

  • Start with a real story, failure, command, bug, or piece of data.
  • Say the opinion early.
  • Provide examples, pull…
Evil Martians 

AI makes design system guardrails mandatory; this framework delivers them

Authors: Anton Lovchikov, Head of Design, Yuri Mandrikov, Frontend Engineer, and Travis Turner, Tech EditorTopics: AI, DX, Agentic development

AI has made implementing and enforcing design systems cheaper than ever. At the cost of speed, this falls through the cracks. But agentic development makes good design system practice non-negotiable. Implement a design system and bring consistency to an existing project.

AI has made implementing and enforcing design systems cheaper than ever. Yet, at the cost of speed, this critical element falls through the cracks. But with agentic development, good design system practice is now non-negotiable. In this post, learn what to do in order to implement a…

OmbuLabs.ai 

The Two Cheapest Agent Eval Signals Both Fail

Once a team stops trusting leaderboards, the next move is usually to build an evaluation of its own. We’ve argued before that benchmark scores are a poor predictor of production agent performance, and the natural follow-up question is what to measure instead.

Two answers come up almost every time, because they are the two cheapest evals to stand up. The first is a panel of LLM judges: ask several models whether an output is factually supported, and take the majority vote. The second is step-level grading: walk the agent’s trajectory one step at a time, score each step, and blame the first one that looks wrong. Neither needs labeled data, and both can be running by the end of the week.

Thr…

The Ruby on Rails Podcast 

Episode 553: The Ruby User Forum with Javier Cervantes

David is joined by Javier Cervantes, co-creator of the Ruby User Forum, to discuss the origins of the project and the need for a persistent gathering place for the Ruby community. After returning to Ruby following several years working with other technologies, Javier found an active ecosystem that was nevertheless scattered across newsletters, blogs, Slack communities, Discord servers, social networks, and individual open-source projects. That experience eventually led to the creation of the Ruby User Forum as a place where conversations can happen more slowly, remain searchable, and continue over days or weeks instead of disappearing into a chat history.

Javier shares what the…

Ruby News 

Ruby 3.4.11 Released

Ruby 3.4.11 has been released. This is a regular scheduled update release includes bugfixes.

Please see the GitHub releases for further details.

Download

The Rails Tech Debt Blog 

Herb on Rails

ERB does not know that it is generating HTML. It finds the <% %> tags, evaluates the Ruby inside them, and concatenates everything else as plain text. Whether the result is valid markup has never been its problem.

Herb changes that. On August 25, 2026, the Ruby on Rails core team merged Add Herb as an HTML-aware ERB implementation, which brings in Herb, an ERB implementation that parses HTML and ERB into a single syntax tree and uses Prism for the Ruby inside the tags. Broken markup can now fail while the template compiles, instead of reaching a browser.

In this article, you will learn what Herb is, how to audit your own views with it today, what it can fix for you, what it cannot, and…

The Rails Tech Debt Blog 

What Happens to Your Ruby Tools With AI?

When we talk about building with AI, most of the attention goes to what’s new. Models, agent frameworks, protocols, and tools seem to appear every week, making it easy to assume that adopting AI means introducing an entirely new technology stack.

But Rails developers already have many of the building blocks needed to create useful AI-assisted workflows. Generators, Rake tasks, command-line interfaces, schemas, tests, and APIs were designed to make software easier to work with by providing structure and predictable behavior. Those same qualities make them well suited for AI coding tools.

In this context, an AI-assisted workflow doesn’t mean building an agent into a Rails application. It…

Sam Ruby 

Campfire, Three Rubies

Three days ago I ran the five-endpoint blog fixture through a 2×3 — stock Rails and Roundhouse's emitted Ruby, each on CRuby+YJIT, JRuby and TruffleRuby — and the result inverted June's: Graal rewarded stock Rails 3.4× and the emit only 1.8×, because a runtime that specializes the interpreter to the program is already doing much of what a compiler that specializes the framework to the application does. The post ended by saying the next experiment was Campfire, Basecamp's chat app, on the same three runtimes, and that TruffleRuby's lack of fork would make it a different experiment.

It is a different experiment, and it has a different answer.

Correction, a few hours after publishing. The…

Noteflakes 

Extralite 3.1.0 is Here!

I’ve just released of Extralite version 3.1.0. This new release implements automatic caching of parametric queries, and updates the bundled SQLite to version 3.53.4.

Extralite is a fast and innovative SQLite wrapper for Ruby with a rich set of features. It provides multiple ways of retrieving data from SQLite databases, makes it possible to use SQLite databases in multi-threaded and multi-fibered Ruby apps, and includes a comprehensive set of tools for managing SQLite databases.

Automatic Query Caching

Extralite now automatically caches the underyling sqlite3_stmt object for any parametric query. Previously, when you ran the same SQL using Database#query_xxx with different parameters,…

JRuby.org News 

JRuby 10.0.7.0 Released

The JRuby community is pleased to announce the release of JRuby 10.0.7.0.

JRuby 10.0.x targets Ruby 3.4 compatibility.

Thank you to our contributors this release, you help keep JRuby moving forward! @aminmansuri, @evaniainbrooks, @gillesbergerp, @jwils, @kares, @lloeki

Notable Changes

Performance

  • Fixed a regression in startup time on MacOS by properly loading native JNR subsystem. #9688, #9689
  • Improve performance of autoloads overridden by an actual require. [#9677], #9675

Java Integration

  • The location of the AppCDS JSA file can now be specified with JRUBY_JSA_HOME. #9667

Standard Library

Def…

Rémi Mercier 

Finishing the square panel – part 02 (Ruby Stained Glass Notes #09)

Today, I finish the square panel, talk about the craftsperson's curse of only seeing imperfections and why adaptability is the name of the game.
Shopify Engineering 

Helix: The internal tool powering our Shopify app's native migration

We built Helix to help LLMs rebuild the Shopify app in Swift and Kotlin, using small checkpoints and strict quality gates to keep the code shippable.
JRuby.org News 

JRuby 10.1.2.0 Released

The JRuby community is pleased to announce the release of JRuby 10.1.2.0.

JRuby 10.1.x targets Ruby 4.0 compatibility.

Thank you to our contributors this release, you help keep JRuby moving forward! @aminmansuri, @drzaiusx11, @evaniainbrooks, @gillesbergerp, @jcharaoui, @jwils, @kares, @lloeki, @makenowjust, @nobu, @sampokuokkanen, @shugo

Notable Changes

Compatibility

Performance

  • Fixed a regression in startup time on MacOS by properly loading native JNR subsystem. #9690
  • Improve performance of…
Ruby on Rails: Compress the complexity of modern web apps 

Agents on Rails: Maximum effort and DeepSeek 4.1 Flash

In the Stage 2 report we shipped 20 feature tickets on Fizzy and promised to explore benchmarking the agents all on max-effort. Now we have run it: every model on the board, same tickets, reasoning turned all the way up. We also tested a new model: DeepSeek 4.1 Flash.

The short version:

  • Effort matters, but only with some agents. GPT-6 Astra (already in first place) went from 35% to 53% success, GPT-5.6 Sol improved from 18% to 28%, and GPT-5.6 Luna performed much better: from 0% to 27% success. Claude, Gemini and Grok barely moved, and Gemini regressed. Muse doubled, from 10% to 20%.
  • It costs. The max sweep cost about $4,100 across all models against $2,250 for the defaults, and runs…
Gusto Engineering - Medium 

Judgment-Based API Governance at Scale

A tangled API schema passes through an illuminated prism and emerges as a clean, consistent network.

Introduction

As products and engineering organizations grow, their API grows with them. New features get shipped, old design patterns coexist with new ones, and decisions that once felt obvious become harder to apply consistently across the entire organization.

At a small scale, maintaining a high-quality API is mostly a matter of shared taste and close collaboration between engineers. At a larger scale, it becomes a systems problem.

How can an organization keep API design consistent and high quality when dozens or hundreds of engineers are making schema changes across many distinct product domains? How do you make sure new APIs follow best practices? And just as importantly, how do you find…

Tim Riley 

Continuations 2026/38: Goodbye Guard

  • I’m trying to get these weeknotes back on track: aiming for a Monday release at the latest. Happy Monday :)

  • The biggest thing I got up to this week was reviewing all of Andrea’s wonderful work adding internal code reloading to Hanami—goodbye Guard! The Dry System piece is now merged, and the core Hanami capability is ready to go after a few small tweaks. All that’s left is for me to get comfy with the new middleware for the reloading web server. This deals with a range of concurrency concerns, so I just need the chance to get my head properly around it.

  • Ryan fixed a couple of issues in rom-rails. Thanks Ryan!

  • CuteCuteYu found a bug in Hanami’s gem detection. Thank you! I checked it out…

Josh Software 

What I learned putting my own text editor into production

A follow-up to “The 5.2 kB editor I had to write because nothing else fit.“ Shipping a package to npm is one thing. Actually using it in the production app it was built for is a different exercise entirely. You find the edge cases nobody would catch in unit tests, because they only show up … Continue reading What I learned putting my own text editor into production
Sam Ruby 

Campfire, One Short

For anyone arriving cold: Roundhouse transpiles Rails applications to other languages; Campfire is Basecamp's MIT-licensed chat app and the one I use to find out what that takes; and Spinel is Matz's ahead-of-time Ruby compiler, so the thing that comes out the far end is a native binary. The measure I trust is Campfire's own test suite, run file by file against that binary and published as a conformance page that clusters the failures by cause.

When Campfire was dockerized that page read 167 of 288 tests, 19 of 54 files green. Today it reads 299 of 300, 54 of 55 files green, none failing to link, and the interpreted lane — the same emitted source run under CRuby — reads the same.

Two moves…

Rails Revelry 

Your Transaction Committed. Did the Job Reach the Queue?

The request fails with SolidQueue::Job::EnqueueError.

That sounds like a clean failure. The controller returned a 500, so the team expects the order transaction to have rolled back. Instead, the order is present in the primary database, the queue database contains no FulfillOrderJob, and retrying the request collides with the order’s uniqueness constraint.

The code responsible for both writes is short:

class FulfillOrderJob < ApplicationJob
  self.enqueue_after_transaction_commit = true

  def perform(order_id)
    # ...
  end
end

Order.transaction do
  order = Order.create!(checkout_token: params[:checkout_token])
  FulfillOrderJob.perform_later(order.id)
end

The exception did not roll back…

code.dblock.org | tech blog 

Serving Markdown for AI Agents, Now as a Jekyll Plugin

Back in January I wrote Serving Markdown for AI Agents: for every page on this blog, there’s also a .md version at the same URL, discoverable via a <link rel="alternate" type="text/markdown"> tag, so AI agents can fetch clean Markdown instead of parsing HTML. It also made me $360, via referral conversions an AI agent apparently generated after reading the clean Markdown version of a post.

That worked, but it lived in this repo as a one-off script, _scripts/render_markdown.rb, wired into the GitHub Actions deploy workflow (needed since GitHub Pages’ native build only allows a small allowlist of plugins, which jekyll-md isn’t on), with the <link> tags added by hand via Liquid and a markdow…

I’ve since extracted all of it into jekyll-md, a proper Jekyll…

Sam Ruby 

Two JITs, Opposite Signs

Three months ago I put the same small Rails application through a 2×2: stock Rails and Roundhouse's emitted Ruby, each on CRuby+YJIT and on JRuby. The claim I drew from it was that the emit — Rails with every request-invariant decision made ahead of time, so what remains is monomorphic sends, resolved constants, and direct string building — is the input the JVM's JIT had been waiting for: stock Rails gained about 2× from the JVM, the emit gained 5–6×, and the two effects multiplied.

Benoit Daloze, who leads TruffleRuby, asked whether it held on TruffleRuby's JVM mode, and was politely doubtful about two of my parameters: "I'm not sure if the 20s warmup or 512MB heap is enough, but no better…

Greg Molnar 

On the recent EuRuKo

EuRuKo happened this week in Brno and even though I was planning to be there, I didn’t go at the end, and I’d like to explain why.

code.dblock.org | tech blog 

In Meetings, Raise Hands Before Reading

I spent five and a half years at AWS before moving (back) to Microsoft, where I work today. At Amazon, many meetings began with silent reading. Instead of presenting a document, the author gave everyone time to read it before the discussion started.

There was a small facilitation trick that made this work surprisingly well: when reading began, everyone raised a hand. When someone finished, they lowered it. The meeting started with all hands up and counted down to zero.

At Microsoft, I found the inverse practice: everyone began with their hands down and raised one when they finished. At the time of writing this, you’ll find me hard at work changing the culture of raised hands at Microsoft,…

Hi, we're Arkency 

TERAZ - live collective ambient experience made with Rails & Tone.js

TERAZ - live collective ambient experience made with Rails & Tone.js

The first time TERAZ actually worked, there were around seventy phones in the audience at the wroclove.rb conference.

Before pressing start, I was still not completely sure what would happen. Local tests are one thing. Seventy people with their own phones, batteries, browsers, volume settings, operating systems, and expectations are another.

I was standing at my laptop, looking at a grid of rectangles on the screen, slowly bringing the instruments in. Each rectangle was one person from the audience. Each phone had been randomly assigned a part: bass, piano, crackling noise, angel pads, drone, or bells.

Then the room…

Ruby on Rails: Compress the complexity of modern web apps 

Rails World 2026 Update: Livestream & Sponsors

As we gear up for Rails World 2026 next week, we’re so grateful to the companies showing up to make the first Rails World in the US a great one.

Below you’ll find every company sponsoring Rails World, and what they are covering (because sponsorship involves so much more than just booths!)

But first, the best news

This year thanks to our Event Partner Shopify, we will livestream the Rails World Opening Keynote for the very first time.

DHH will lay out his most defining vision yet for what comes next for Rails, and what it means for all of us who build software with it. At this pivotal moment in technology, this is one not to miss.

Tune in early for a pre-opening chat hosted by Shopify’s …

The Rails Tech Debt Blog 

Rails 8.2: The HTTP QUERY Method

RFC 10008, published in June 2026, defines the QUERY method as safe and idempotent like GET, and it carries its query in the request body like POST. Ruby on Rails merged support for QUERY on August 14, 2026, under the 8.2.0 milestone.

I set up a small application on edge Rails to check it working. The routing and the request object are ready, but the parts of the specification that make QUERY more than a POST with better manners are not quite there yet, since Rails parses only JSON bodies and does not enforce the content type rule RFC 10008 requires. In this article, we will check how the QUERY method works in Rails, how to route and test it, how Puma is handling it, and which pieces of…

Ruby on Rails: Compress the complexity of modern web apps 

JSON schema cache, herb:check, and more!

A week of things that should just work: schema cache that loads in JSON, PostgreSQL names that resolve to one table, Active Storage that boots even when libvips is missing or too old, and Live responses that finally carry the default headers. Here’s what’s new in Rails:

Watch the Rails World 2026 Opening Keynote live
DHH’s opening keynote is streaming for anyone who can’t get to Austin. He’ll cover what’s new in Rails, what’s coming next, and where the framework is headed. Tune in at 9:30 AM Austin, 7:30 AM Pacific, 10:30 AM Eastern, 3:30 PM UK, 4:30 PM Central Europe, or 11:30 PM Japan. The livestream is made possible by Rails World Event Partner Shopify.

Active Record schema caches can…

Remote Ruby 

Navigating the Labyrinth of Webhooks and APIs

Chris, Andrew, and David are back with a conversation that starts with Rails World plans. They break down APIs, webhooks, and persistent connections, using everything from thermostats to Stripe to explain how systems communicate and recover when things go wrong. From there, Chris shares what caught his eye in PlanetScale’s new Postgres sharding work, before the conversation shifts heavily toward AI-assisted programming, where the tools are surprisingly capable one minute and making baffling architectural decisions the next. They also explore how AI is changing Chris’s work on Jumpstart and Hatchbox, improving Rails actionable errors, tackling years-old Android bugs, and potentially…

Sam Ruby 

Roundhouse Released

Five months ago, yesterday: Initial commit: typed IR, Ruby round-trip, Rust struct emit. Yesterday, Matz on stage: 5x the throughput; 366 MB against 4.6 GB, referring to Campfire → Roundhouse → Spinel Today is the first release. Highlights: Analyzes, from an in-browser IDE, an LSP, or an MCP server. Transpiles a blog app with Action Cable, Turbo Stream, and Tailwind CSS to a dozen languages. Compiles Campfire with Spinel into a Docker image. Documentation, Nate says, is claudeslop. Guilty. If that or anything else bothers you, you know what to do.
Sam Ruby 

Spinel at Your Fingertips

For anyone arriving cold: Spinel is Matz's ahead-of-time Ruby compiler. It reads a whole program, infers a type for every value it can, and emits C; where inference succeeds you get an unboxed sp_int in a C struct, and where it cannot settle on one type a value is widened to untyped and takes a boxed, dispatched slow path. It also refuses outright a documented list of things it does not compile. Those two verdicts — refused, and widened — are the whole story of whether a program is fast under Spinel, and until this week the way to see them was spinel --emit-types writing a JSON file, --emit-rbs writing the inferred signatures, and the refusals on stderr.

I wanted them at my fingertips.…

Awesome Ruby Newsletter 

💎 Issue 539 - OpenAI agents carried out an undisclosed attack on RubyGems

André Arko 

Beyond jj: config & tools ecosystem

This post was originally given as a talk at JJ Con 2026. The slides are also available.

Hello! Welcome to “beyond jj”, where we’re going to take a look at the jj ecosystem: commands, configurations, and tools made to work with jj. It’s partly a follow-up to my talk at JJCon last year, where I surveyed jj configurations across the community, but we’ll get there in a minute.

My practical qualifications to give a talk about jj basically come down to “I like trying new things, and I’m very excited about jj”. My impractical qualifications to give a talk about jj come down to “Steve Klabnik was my roommate once, so I can ask him to put my ideas into the official jj docs”. Thanks in advance,…

avdi.codes 

https://avdi.codes/184910-2/?utm_source=rss&utm_medium=rss&utm_campaign=184910-2

An open fascist is building one of the bigger sources of funding for open source fully under his individual control and sucks up a lot of money that otherwise might have gone to liberatory projects. Community projects. Antifascist projects.

tante: Power Grab

Ruby Weekly 

Did AI agents attack RubyGems?

#​817 — September 17, 2026

Read on the Web

Ruby Weekly

Researchers Tie RubyGems' 'GemStuffer' Campaign to OpenAI Agents — Researchers say May's RubyGems spam flood came from OpenAI agents that ran code on RubyDoc.info and probed a key-leaking CDN bug. OpenAI has confirmed its agents were involved, but describes their actions as "benign tasks", while Ruby Central finds no evidence of successful key theft.

Kitts, Larsen, and Von Arx

💡 Truffle Security, which disclosed the caching bug in July, digs into the code from May that targeted it.

Upgrading Rails Is Dead Simple Now. So Why Are You Behind? — Wouldn't it be…

Karol Galanciak 

From collecting payments to distributing revenue: the FinTech system behind Smily

Collecting a payment sounds like a reasonably well-defined problem. A traveler pays for a booking, the payment succeeds, and the property manager receives the money.

Except that the property manager might only be entitled to part of it. The rest belongs to the owner. A booking channel might have already deducted its commission and collected a tax. The booking might include Travelers’ Fees or Cancellation Protection. And the bank transfer might cover twenty bookings, an adjustment to an older reservation, and a deduction that has nothing to do with any of them.

Suddenly, “the payment succeeded” tells us surprisingly little about what should happen next.

At Smily, we built the system that…

Rails Designer Blog 

Custom Actions in Attractive.js: one interface, from small to big

In last week’s announcement, I promised that when the built-in actions aren’t enough, you can write your own. Let me show you how, because this is what was bugging me most: why pull in another library when Attractive.js can do it as well?

Next to that I will also highlight some extra goodies and the bundled extensions that can now be (optionally) added.

Start with a one-liner

The quickest custom action is the js: prefix. It evaluates a JavaScript expression on the element, so you can do things too small for a full action:

<button @click="js:this.textContent=1">0 (I will become 1)</button>

Use it for one-liners only. It goes through the full action pipeline (so all events works as well as …

Sam Saffron's Blog - Latest posts 

About the Blog category

(Replace this first paragraph with a brief description of your new category. This guidance will appear in the category selection area, so try to keep it below 200 characters.)

Use the following paragraphs for a longer description, or to establish category guidelines or rules:

  • Why should people use this category? What is it for?

  • How exactly is this different than the other categories we already have?

  • What should topics in this category generally contain?

  • Do we need this category? Can we merge with another category, or subcategory?

Josh Software 

When Your Zod Schema Lives in the Database: A Builder Pattern Story

This is a story about a form that validated itself, not because the schema was hardcoded, but because we built it at runtime. I was working on a feature where admins could spin up their own forms. Drag a field in, mark it required, set a max length, save, ship. By the time an end-user … Continue reading When Your Zod Schema Lives in the Database: A Builder Pattern Story
Rails at Scale 

Ractor-age Rails: A How-To Guide

In our last post on Ractors, Edouard demonstrated the potential benefits of using Ractors in a Rails application. He also explained how our team has been working towards making Rails and its dependencies Ractor-friendly. While we’ve been able to get smaller applications running on Ractors, we still have a long way to go to unlock larger applications, which use more features of Rails and many more gems. However, we have reached a good point where we can start to talk about the process itself.

In this post, I want to discuss some of the patterns we’ve used to refactor code to work with Ractors. But first, let’s talk about why any of this is necessary by looking at the constraints that…

code.dblock.org | tech blog 

Porting a Discord Bot to Microsoft Teams, Entirely With AI

Slava (slack-strava) connects a Strava account to a chat and posts a card for every activity, complete with map, pace, and elevation, plus commands like connect, disconnect, stats, and leaderboard. In 2023 I ported Slava to Discord by hand, evening by evening over about three weeks, and it took most of that stretch to get a working bot called Strada (discord-strava). This week I ported the same app to Microsoft Teams as Strata (teams-strava) in 3 days instead of the 3 weeks the Discord port took, using time carved out during the Microsoft Global Hackathon. By “I”, I mean GitHub Copilot CLI and I.

Strata posting a Strava activity to a Teams channel

The 2023 Baseline

discord-strava’s git history is a fair record of how long a manual port…

Tim Riley 

Continuations 2026/37: Response streaming

  • These weeknotes are pulling into the station a little late, because I’ve been busy starting my new job! I’ve joined the crew at HotDoc, as a manager slash engineer. It’s been a great time so far!

  • I noticed Dry Monads CI was failing in production due to version 3.0 of the json gem removing the json/add custom serialization machinery (and for good reason). I switched this over to the new JSON::Coder API and pushed up v1.11.0 of Dry Monads.

  • I forgot to mention it last week, but we landed the styled text support in Dry CLI! I’m really happy with the collaborative process on this one (Aaron and I both contributing different things to the work) as well as the final result: a flexible and…

The Ruby on Rails Podcast 

Episode 552: Hatchbox and GoRails in the age of AI with Chris Oliver and Collin Jilbert

Chris Oliver and Collin Jilbert join David for a candid conversation about the changing economics of building products for the Ruby on Rails community in the age of AI.

Chris traces the history of GoRails from its beginnings as an attempt to fill the void left by RailsCasts, through to the creation of Hatchbox and Jumpstart, and explains how those products evolved together over more than a decade. But the rapid improvement of AI coding assistants has dramatically changed how developers learn and work. Instead of searching for a tutorial, watching a screencast, and adapting an example to their application, developers can increasingly ask an AI tool to work directly inside their…

RubyGems Blog 

4.0.21 Released

RubyGems 4.0.21 includes enhancements and Bundler 4.0.21 includes enhancements and bug fixes.

To update to the latest RubyGems you can run:

gem update --system [--pre]

To update to the latest Bundler you can run:

gem install bundler [--pre]
bundle update --bundler=4.0.21

RubyGems Release Notes

Enhancements:

  • Stop vendoring resolv for two regexps. Pull request #9877 by Hiroshi SHIBATA
  • Normalize absolute symlink targets during gem extraction. Pull request #9860 by Hiroshi SHIBATA
  • Installs bundler 4.0.21 as a default gem.

Bundler Release Notes

Enhancements:

  • Don’t update bundler to a prerelease unless asked for one. Pull request #9869 by Hiroshi SHIBATA
  • Reject Bundler…

Bug fixes:

  • Sup…
Posts on Kevin Murphy 

Rocky Mountain Ruby 2026 Recap

Rocky Mountain Ruby 2026 🔗

This post is not intended as a review of any of the talks, but to highlight the variety of great work from all involved. I hope you’ll seek out the full videos of all the sessions that interest you once they are available.

Day 1 🔗

InstiLLMent of Successful Practices in an Agentic World 🔗

Thanks to everyone for joining me to start the program.

Kevin at Rocky Mountain Ruby 2026📸 Credit: Rachael Wright-Munn

Confident On-Call: Building Incident Response Skills as a Ruby Engineer 🔗

Sonja Peterson provided an excellent case to demonstrate how on-call work can be improved through better rotation onboarding, active incident management, and intentional post-mortems.

Sonya at Rocky Mountain Ruby 2026

Beyond Senior: Consider the staff path! 🔗

Joel…