Riding Rails

The official Ruby on Rails (RoR) framework blog

Potential XSS Vulnerability in Ruby on Rails Applications


8 months ago by aaronp on Riding Rails.
The XSS prevention support in recent versions Ruby on Rails allows some string operations which, when combined with user supplied data, may leave an 'unsafe...

News from the Documentation Front


8 months ago by fxn on Riding Rails.
New Configuration Guide Rails 3.1 will come with a new comprehensive guide about configuring Rails applications written by Ryan Bigg (@ryanbigg). The current...

[ANN] Rails 3.0.8.rc3 (third time is the charm!)


8 months ago by aaronp on Riding Rails.
Hey everybody! I've pushed Rails 3.0.8.rc3. Hopefully this release candidate takes care of all the outstanding issues remaining. To see what has changed...

[ANN] Rails 3.0.8.rc2


9 months ago by aaronp on Riding Rails.
Hey folks! I've pushed 3.0.8.rc2. I want to give a big thanks to Philip Arndt and Robert Pankowecki for reporting regressions in 3.0.8.rc1! We've fixed...

[ANN] Rails 3.0.8.rc1


9 months ago by aaronp on Riding Rails.
ZOMG HI EVERYBODY!!!! HAPPY WEDNESDAY (UTC-7). I am EXCITED, PLEASED, and even MORE EXCITED to announce the release of the Rails 3.0.8 released candidate...

Rails 3.1: Release candidate


9 months ago by David Heinemeier Hansson on Riding Rails.
As I promised at RailsConf, we’re finally good to go on the Rails 3.1: Release Candidate. This is a fantastically exciting release. We have three...

Ruby Hero Awards 2011


10 months ago by Gregg Pollack on Riding Rails.
It’s that time again to take a moment to think about those who have impacted the Ruby community this year but have not received the recognition...

Rails 3.0.6 has been released!


10 months ago by aaronp on Riding Rails.
Hi everybody! Rails 3.0.6 has been released! Let's get the serious business out of the way first: Rails 3.0.6 contains an important security fix! Please...

Rails 3.0.5 has been released!


12 months ago by spastorino on Riding Rails.
Aaron Patterson showed us some tenderlove this week by releasing Rails 3.0.5. Have a peek at what got updated. Bugs Fixed Fix when gzip returns a...

CSRF Protection Bypass in Ruby on Rails


12 months ago by Michael on Riding Rails.
There is a vulnerability in Ruby on Rails which could allow an attacker to circumvent the CSRF protection provided. This vulnerability has been assigned...