138 wires and counting

$ follow Rails

Keep up with Rails in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-25
stories 57

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

Herb becomes the 8.2 default, Ractor-safe connections land

By RepoJournal · Filed · About Rails · Composed from the cited sources · methodology

Rails' next framework defaults swap the ERB compiler for Herb and give Active Record a connection handler that works in non-main ractors, while the site patches a security.txt gap and lemans hardens its agent sandbox.

Add a framework default to compile HTML+ERB templates through Herb rails/rails

by marcoroth

config.action_view.erb_implementation now accepts :herb alongside :erubi, and config.load_defaults 8.2 sets it to :herb, so applications that opt into the new defaults compile HTML+ERB through Herb. Existing apps stay on erubi until they load the 8.2 defaults.

Active Record Ractor-friendly connection handling rails/rails

by gmcgibbon

Active Record gains a connection handler, pool, and proxy that replace the defaults for non-main ractors, selected by a main ractor check at ActiveRecord::Base.connection_handler. Non-ractorized applications are unaffected, and it gives ractorized apps a way to query outside the main ractor.

Manually specify security validator in herb checker rails/rails

by Gannon McGibbon

The herb checker now specifies its security validator manually because it is no longer the default in Herb 0.11. The merged 0.11 fix lands the same change on main.

Merge pull request #718 from robbyrussell/task/rr-693-add-security-txt rails/website

by Rafael Mendonça França

The Rails website serves /.well-known/security.txt per RFC 9116, giving vulnerability reporters a canonical contact path instead of an educated guess.

Merge pull request #725 from koic/re_enable_jekyll_redirect_from rails/website

by Rafael Mendonça França

jekyll-redirect-from is enabled again, restoring redirects that had been 404ing on trailing-slash URLs; the rest of the website desk is cosmetic, adding a since and handle for Mike and matching the core members section to the committers section width.

First prepares for ms-* tasks (more network allowance + more run stability + remove mtime leak) rails/lemans

by ardecvz

lemans' miniswen runner gets --allow-hosts to proxy jailed commands to allowlisted hosts, --workdir for per-task working directories, and fixes so a background process holding a command's output no longer hangs the agent.

Quick answers

What shipped in Rails on September 25, 2026?
Rails' next framework defaults swap the ERB compiler for Herb and give Active Record a connection handler that works in non-main ractors, while the site patches a security.txt gap and lemans hardens its agent sandbox. In total, 39 commits, 16 pull requests, and 2 releases landed.
Who contributed to Rails on September 25, 2026?
6 developers shipped this update, including Gannon McGibbon, marcoroth, Jean Boussier, Rafael Mendonça França, ardecvz, and Alexander Baygeldin.
What were the notable Rails updates?
Add a framework default to compile HTML+ERB templates through Herb, Active Record Ractor-friendly connection handling, and Manually specify security validator in herb checker.