#railssecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #railssecurity, aggregated by home.social.
-
bundler-audit is necessary and not sufficient. CVE-2026-66066 hits default Rails 7.0+ setups using vips, and patching the gem is only half of it. You also need libvips 8.13 or newer, and gem-level scanning never sees the system library.
https://go.fastruby.io/agj
#RailsSecurity #Ruby #RailsUpgrade -
bundler-audit is necessary and not sufficient. CVE-2026-66066 hits default Rails 7.0+ setups using vips, and patching the gem is only half of it. You also need libvips 8.13 or newer, and gem-level scanning never sees the system library.
https://go.fastruby.io/agj
#RailsSecurity #Ruby #RailsUpgrade