THE SIMPLEST CHANNEL
Advisories,
in your inbox.
Verify an address, choose it for an app, and the next Rails advisory arrives with the investigation brief included.
Verify an address
In Settings, under Notification addresses, enter an address and click Send verification email. Open the message, follow the link, and press Confirm notification address while signed in to the workspace that asked for it. Links expire after one hour and work once. Opening the link alone does nothing, so mail scanners cannot consume it.
Up to five addresses per workspace. If a confirmation does not arrive, wait fifteen minutes and enter the address again. An address is a destination only; it cannot sign in or recover the workspace.
Choose it for an app
In Apps, set the delivery mode to Email or Both and pick a verified address. Email-only apps are active immediately. In Both mode, email can start delivering while the webhook still awaits its handshake.
What the email contains
- Subject
[Rails CVE] <app name>: <CVE or title>. - The advisory title, severity, and canonical link.
- The event ID and type: published, updated, or withdrawn.
- The complete investigation brief, ready to paste into your coding agent.
- A link to your dashboard to pause or change the subscription.
A connection test uses the same format and says explicitly that it is a test.
Delivery and retries
Up to eight attempts, waiting 5, 10, 20, 40, 80, 160, and 320 minutes between them. The delivery log shows accepted when the provider took the message. Inbox arrival and bounces are not tracked, so allow-list the sender if messages go missing.
Removing an address cancels its pending deliveries and clears it from any app that used it. Those apps show Needs destination until you choose another. Email and webhook attempts for the same event are independent: a failing webhook never resends the email.
Verify an address →