THE RAILS SECURITY RELAY
Security updates.
Right on track.
Rails advisories, delivered to your codebase. Get a signed webhook and a clear starting point for your coding agent.
Opt in. Stay informed. Keep humans in the loop.
THE SOURCE
Rails publishes an advisory
Canonical details. Exact affected versions.
THE SIGNAL
Your webhook receives it
Signed, timestamped, and retried.
THE NEXT STEP
Your agent investigates
Repository evidence. A fix for you to review.
From the Rails maintainers
Signed with HMAC-SHA256Agent-ready investigation briefsNo repository access requiredTHE LATEST SIGNALS
Know what needs attention.
Possible arbitrary file read and remote code execution in Active Storage variant processing
activestorage
Possible XSS vulnerability in Action Pack debug exceptions
actionpack
Possible XSS vulnerability in Action View tag helpers
actionview
Source: rails/rails on GitHub. Last checked Sep 22, 2026 at 17:15 UTC. Checked every five minutes.
LESS INBOX. MORE CONTEXT.
A useful first step,
already written.
Every advisory comes with a focused investigation brief. Give it to your agent to check your dependencies, trace affected code, and propose the next step.
Your code stays with you. Your agent works in your environment. You decide what gets changed.
Explore an investigation brief →