home.social

#railssecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #railssecurity, aggregated by home.social.

  1. bundler-audit is necessary and not sufficient. CVE-2026-66066 hits default Rails 7.0+ setups using vips, and patching the gem is only half of it. You also need libvips 8.13 or newer, and gem-level scanning never sees the system library.
    go.fastruby.io/agj
    #RailsSecurity #Ruby #RailsUpgrade

  2. bundler-audit is necessary and not sufficient. CVE-2026-66066 hits default Rails 7.0+ setups using vips, and patching the gem is only half of it. You also need libvips 8.13 or newer, and gem-level scanning never sees the system library.
    go.fastruby.io/agj
    #RailsSecurity #Ruby #RailsUpgrade