Skip to content

Releases: rails/rails

8.1.4

Choose a tag to compare

@rafaelfranca rafaelfranca released this 24 Sep 14:19
v8.1.4
c3466ea

Active Support

  • Fix the debug error page rendering for SyntaxErrors with multi-line messages.

    Marco Roth

  • Make ActiveSupport::JSON.decode compatible with the upcoming json 3.0 gem.

    Earlopain

  • Fix number_to_human_size crashing for sizes above a terabyte by supporting
    petabyte, exabyte, and zettabyte storage units.

    Kenta Ishizaki

  • Fix Range#sole raising NoMethodError when the enumerable core extension
    isn't already loaded.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::FileStore raising NameError for FileUtils
    when fileutils isn't already loaded.

    Kenta Ishizaki

  • Fix Enumerable#in_order_of with filter: true dropping nil elements
    explicitly named in the series.

    Kenta Ishizaki

  • Keep HashWithIndifferentAccess#filter returning a HashWithIndifferentAccess
    instead of a plain Hash.

    Kenta Ishizaki

  • Fix number_to_human and number_to_human_size crashing when :precision is nil.

    Kenta Ishizaki

  • Fix ActiveSupport::InheritableOptions#to_h to recursively flatten nested
    InheritableOptions parents.

    Andrew Novoselac

  • Fix ActiveSupport::StructuredEventSubscriber.debug_only leaking debug-only
    methods across subscriber subclasses.

    Kenta Ishizaki

  • Fix ActiveSupport::Inflector#transliterate mutating the caller's string.

    Kenta Ishizaki

  • Fix Hash.from_xml raising Date::Error on type="date" values surrounded
    by whitespace.

    Kenta Ishizaki

  • Fix Time#advance and DateTime#advance mutating the options hash passed
    by the caller.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::MemoryStore#cleanup raising NoMethodError when
    used with a non-DupCoder serializer.

    Kenta Ishizaki

  • Fix String#truncate with :separator misbehaving when the :omission is
    longer than the target length.

    Kenta Ishizaki

  • Fix ActiveSupport::Cache::Store#delete_multi mutating the names array passed
    by the caller.

    Kenta Ishizaki

  • Fix number_to_currency crashing on a negative number when :precision is nil.

    Kenta Ishizaki

  • Fix TimeZone#strptime with %s dropping the sub-second fraction of the timestamp.

    Kenta Ishizaki

  • Fix HashWithIndifferentAccess.new dropping a falsy (false or 0) default
    value from the source hash.

    Kenta Ishizaki

  • Fix Range#include? and Range#=== raising on exclusive non-integer sub-ranges.

    Kenta Ishizaki

  • Fix number_to_delimited corrupting numbers that begin with a + or - sign.

    Kenta Ishizaki

  • Fix ActiveSupport::InheritableOptions#== raising NoMethodError when compared
    with a non-Hash object.

    Kenta Ishizaki

  • Fix Enumerable#in_order_of with filter: false dropping elements whose keyed
    value is nil.

    Hammad Khan

  • Stop the DRb service when shutting down parallel test workers, preventing it
    from lingering after the test run.

    Shuta Mugikura

  • Preserve the encoding of ActiveSupport::SafeBuffer values round-tripped through
    ActiveSupport::MessagePack.

    Rafael MendonΓ§a FranΓ§a

  • Fix number_to_phone without an area code stripping a leading delimiter when the
    number itself coincidentally starts with the delimiter string.

    Tahsin Hasan

  • Update ActiveSupport::TimeZone mappings to use the current IANA identifiers
    Europe/Kyiv (was Europe/Kiev) and Asia/Yangon (was Asia/Rangoon).

    tsymbalenkovlad

  • Use the faster string-based delimiter logic by default in number_to_delimited,
    instead of the regular expression fallback.

    Shinichi Maeshima

  • Preserve the requested key order in ActiveSupport::Cache::Store#fetch_multi
    when a local cache is active.

    Previously, if some keys were served from the local cache and others from the
    underlying store, fetch_multi returned the local cache hits first instead of
    following the order of the requested keys.

    Mueez Afzal

  • Fix String#parameterize raising TypeError when separator is nil.

    parameterize already treats a nil separator the same as an empty one when
    squeezing and trimming separators, but raised TypeError before reaching that
    point. A nil separator now behaves like "", removing the unwanted characters.

    "Donald E. Knuth".parameterize(separator: nil) # => "donaldeknuth"

    Hammad Khan

  • Add RedisClient::Error to ActiveSupport::Cache::RedisCacheStore's failsafe rescue list.

    The redis-rb gem normally translates RedisClient::* errors into Redis::* errors but in
    some rare cases, such as when using sentinels, RedisClient::* errors may slip through.

    David Arrunategui

  • Fix ActiveSupport::Duration#in_minutes, #in_hours, #in_days,
    #in_weeks, #in_months, and #in_years truncating sub-second precision.

    These methods divided the duration's integer second count (in_seconds,
    aliased to to_i) instead of its exact value, so any fractional second was
    silently dropped before the conversion.

    # Before
    90.5.seconds.in_minutes # => 1.5
    
    # After
    90.5.seconds.in_minutes # => 1.5083333333333333

    Kenta Ishizaki

  • Fix JSON encoding of non-String Hash keys.

    The old encoder would simply call to_s on them, the newer encoder
    would incorrectly call as_json instead.

    In the case of Time, DateTime and TimeWithZone this would result
    in different serialization of time keys: "2009-01-01T12:30:00.000Z" (arguably better)
    instead of "2009-01-01 12:30:00 UTC" (how it used to be).

    Kenta Ishizaki

  • Fix number_to_phone dropping only the first character of a
    multi-character :delimiter when no area code is present.

    The leading delimiter produced by an empty first capture group was
    stripped with slice!(0, 1), which assumed a single-character
    delimiter. Multi-character (and multibyte) delimiters now work:

    number_to_phone(5551234, delimiter: " - ")  # => "555 - 1234"
    # was "- 555 - 1234"
    

    Kenta Ishizaki

  • Fix titleize inflector to consider Unicode characters

    "Δ‡asim Δ‘ipa".titleize # => "Δ†asim Đipa"

    Eldin Guzin

Active Model

  • Fix ActiveModel::Errors#import mutating the override options hash passed to it.

    Kenta Ishizaki

  • Fix normalizes not detecting in-place changes for attributes whose database
    cast type differs from the attribute type (e.g. JSON columns), causing
    normalization to be skipped on validation.

    Chedli Bourguiba

  • Fix alias_attribute accumulating duplicate entries in aliases_by_attribute_name
    when called multiple times with the same arguments.

    Nicholas Jakobsen

  • Fix normalizes re-applying normalizations on every validation of an
    unpersisted record, and speed up validation of normalized attributes.

    The in-place mutation check re-ran the normalizer on every valid? of an
    unpersisted record: wasteful for idempotent normalizers and compounded the
    result for non-idempotent ones. Normalizations are now re-applied only on a
    genuine in-place mutation.

    Yaroslav Markin

  • Limit the size of strings ActiveModel::Type::Integer will coerce with to_i.

    Calling to_i on very long strings can take a long time and could be used as
    a DoS vector. Integer casting now only considers the first _limit * 4 bytes
    of a string (16 bytes for a default 4-byte integer, 32 bytes for an 8-byte
    bigint), which is enough to hold the maximum representable value plus a sign
    or a short slug suffix.

    Aaron Patterson, Jean Boussier

Active Record

  • Avoid deadlocks when concurrent find_or_create_by calls read back the same
    record within MySQL transactions.

    Use a shared lock for the read after a duplicate insert, preserving visibility
    under REPEATABLE READ without upgrading competing shared locks to exclusive locks.
    This also applies to create_or_find_by and the bang variants of both methods.

    Fixes #54281.

    Kirsten Westeinde

  • Filter the database password out of failed db: task command error messages.

    Ngan Pham

  • Fix ActiveRecord::TypeCaster::Connection sometimes leaking a checked-out
    connection.

    Hartley McGuire

  • Fix PostgreSQL exclusion constraints with multiline expressions being parsed
    incorrectly during schema introspection.

    Jake McAllister

  • Fix async ActiveRecord::StatementCache#execute raising an error for
    out-of-range bind values instead of returning an empty result.

    viralpraxis

  • Fix where clauses with column-tuple syntax not resolving references to
    other tables.

    Chris Gunther

  • Fix distinct: true being ignored by average.

    Kenta Ishizaki

  • Fix belongs_to change tracking for composite foreign keys.

    Only the first foreign key column was checked for changes; now all foreign
    key columns are checked.

    Anas Khan

  • Make add_column(if_not_exists: true) reversible.

    Kenta Ishizaki

  • Quote the index name in MySQL enable_index and disable_index.

    Unquoted index names containing special characters could cause SQL syntax
    errors.

    Kenta Ishizaki

  • Make remove_foreign_key(if_exists: true) reversible.

    Kenta Ishizaki

  • Fix distinct: true being ignored by grouped sum.

    Kenta Ishizaki

  • Return an ActiveRecord::Promise from async_ids on a contradictory
    relation, instead ...

Read more

7.2.4

Choose a tag to compare

@rafaelfranca rafaelfranca released this 24 Sep 16:28
v7.2.4
48e05e6

Active Support

  • Improve number_to_delimited performance when delimiter_pattern is not specified.

    Shinichi Maeshima

  • Silence Dalli 4.0+ warning when using ActiveSupport::Cache::MemCacheStore.

    zzak

  • Fix ActiveSupport::Inflector.humanize with international characters.

    ActiveSupport::Inflector.humanize("Γ‘Γ‰ΓΓ“Γš")  # => "Áéíóú"
    ActiveSupport::Inflector.humanize("Π°Π‘Π’Π“Π”Π•") # => "АбвгдС"

    Jose Luis Duran

Active Model

  • No changes.

Active Record

  • Fix performance regression in method_missing for virtual SELECT alias
    attributes.

    Fixes #57183.

    Hammad Khan

  • Fix support for table names containing hyphens.

    Evgeniy Demin

  • Improve PostgreSQLAdapter resilience to Timeout.timeout.

    Better handle asynchronous exceptions being thrown inside
    the reconnect! method.

    This may fixes some deep errors such as:

    undefined method `key?' for nil:NilClass (NoMethodError)
              if !type_map.key?(oid)
    

    Jean Boussier

  • Fix eager_load when loading has_many assocations with composite primary keys.

    This would result in some records being loaded multiple times.

    Martin-Alexander

Action View

  • Fix strict locals parsing to handle multiline definitions.

    Said Kaldybaev

Action Pack

  • Fix ActionController::UnknownHttpMethod to return 405 Method Not Allowed
    instead of 500 Internal Server Error.

    Nicolas Vandenbogaerde

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • No changes.

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • Fixed the default Dockerfile to properly include the vendor/ directory during bundle install.

    Zhong Sheng

Guides

  • No changes.

8.1.3.1

Choose a tag to compare

@rafaelfranca rafaelfranca released this 29 Jul 14:59
v8.1.3.1
3989ebf

Active Support

  • No changes.

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • No changes.

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Disable libvips's unfuzzed image loaders and savers.

    libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only
    safe for trusted content. Active Storage will call Vips.block_untrusted(true) to disable them
    while booting. An application that needs a specific loader or saver may re-enable it in an
    initializer.

    This is a breaking change for applications that process image types with an unfuzzed loader or
    saver. Variant transformation of BMP, ICO, and PSD attachments will raise Vips::Error, and
    analysis of these and other types such as SVG, JPEG XL, JPEG 2000, and Netpbm will no longer
    record width and height. Requesting an unfuzzed output format, typically FITS, JXL, or
    anything delegated to ImageMagick, will also raise Vips::Error. Attaching, storing, and
    downloading are unchanged.

    An application seeing Vips::Error raised during image transformation may wish to remove the
    affected content types from config.active_storage.variable_content_types in an initializer.
    Active Storage will then treat those attachments as not variable and will not generate variants
    for them. This most often matters to an application that transforms images during a request
    rather than in a background job, where the failure surfaces as an error response instead of a
    failed job.

    Rails.application.config.active_storage.variable_content_types -=
      %w[ image/bmp image/vnd.microsoft.icon image/vnd.adobe.photoshop ]

    Applications using the :mini_magick variant processor will see no change in how their
    attachments are processed, but the loaders and savers will be disabled process-wide whenever
    ruby-vips is installed, and the version requirements below will still apply. Such an application
    may remove ruby-vips from its Gemfile to avoid both.

    The minimum supported version of libvips is now 8.13, and the minimum supported version of
    ruby-vips is now 2.2.1. These are the earliest versions that are capable of disabling untrusted
    operations. When ruby-vips is installed and either minimum is not met, Active Storage will raise
    a RuntimeError while booting rather than run in an unsecurable environment.

    [GHSA-xr9x-r78c-5hrm]
    [CVE-2026-66066]

    Mike Dalessio

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • No changes.

Guides

  • No changes.

8.0.5.1

Choose a tag to compare

@rafaelfranca rafaelfranca released this 29 Jul 15:08
v8.0.5.1
beef74d

Active Support

  • No changes.

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • No changes.

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Disable libvips's unfuzzed image loaders and savers.

    libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only
    safe for trusted content. Active Storage will call Vips.block_untrusted(true) to disable them
    while booting. An application that needs a specific loader or saver may re-enable it in an
    initializer.

    This is a breaking change for applications that process image types with an unfuzzed loader or
    saver. Variant transformation of BMP, ICO, and PSD attachments will raise Vips::Error, and
    analysis of these and other types such as SVG, JPEG XL, JPEG 2000, and Netpbm will no longer
    record width and height. Requesting an unfuzzed output format, typically FITS, JXL, or
    anything delegated to ImageMagick, will also raise Vips::Error. Attaching, storing, and
    downloading are unchanged.

    An application seeing Vips::Error raised during image transformation may wish to remove the
    affected content types from config.active_storage.variable_content_types in an initializer.
    Active Storage will then treat those attachments as not variable and will not generate variants
    for them. This most often matters to an application that transforms images during a request
    rather than in a background job, where the failure surfaces as an error response instead of a
    failed job.

    Rails.application.config.active_storage.variable_content_types -=
      %w[ image/bmp image/vnd.microsoft.icon image/vnd.adobe.photoshop ]

    Applications using the :mini_magick variant processor will see no change in how their
    attachments are processed, but the loaders and savers will be disabled process-wide whenever
    ruby-vips is installed, and the version requirements below will still apply. Such an application
    may remove ruby-vips from its Gemfile to avoid both.

    The minimum supported version of libvips is now 8.13, and the minimum supported version of
    ruby-vips is now 2.2.1. These are the earliest versions that are capable of disabling untrusted
    operations. When ruby-vips is installed and either minimum is not met, Active Storage will raise
    a RuntimeError while booting rather than run in an unsecurable environment.

    [GHSA-xr9x-r78c-5hrm]
    [CVE-2026-66066]

    Mike Dalessio

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • No changes.

Guides

  • No changes.

7.2.3.2

Choose a tag to compare

@rafaelfranca rafaelfranca released this 29 Jul 15:05
v7.2.3.2
8ec292f

Active Support

  • No changes.

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • No changes.

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Disable libvips's unfuzzed image loaders and savers.

    libvips flags some of its loaders and savers as "unfuzzed" or "untrusted", meaning they are only
    safe for trusted content. Active Storage will call Vips.block_untrusted(true) to disable them
    while booting. An application that needs a specific loader or saver may re-enable it in an
    initializer.

    This is a breaking change for applications that process image types with an unfuzzed loader or
    saver. Variant transformation of BMP, ICO, and PSD attachments will raise Vips::Error, and
    analysis of these and other types such as SVG, JPEG XL, JPEG 2000, and Netpbm will no longer
    record width and height. Requesting an unfuzzed output format, typically FITS, JXL, or
    anything delegated to ImageMagick, will also raise Vips::Error. Attaching, storing, and
    downloading are unchanged.

    An application seeing Vips::Error raised during image transformation may wish to remove the
    affected content types from config.active_storage.variable_content_types in an initializer.
    Active Storage will then treat those attachments as not variable and will not generate variants
    for them. This most often matters to an application that transforms images during a request
    rather than in a background job, where the failure surfaces as an error response instead of a
    failed job.

    Rails.application.config.active_storage.variable_content_types -=
      %w[ image/bmp image/vnd.microsoft.icon image/vnd.adobe.photoshop ]

    Applications using the :mini_magick variant processor will see no change in how their
    attachments are processed, but the loaders and savers will be disabled process-wide whenever
    ruby-vips is installed, and the version requirements below will still apply. Such an application
    may remove ruby-vips from its Gemfile to avoid both.

    The minimum supported version of libvips is now 8.13, and the minimum supported version of
    ruby-vips is now 2.2.1. These are the earliest versions that are capable of disabling untrusted
    operations. When ruby-vips is installed and either minimum is not met, Active Storage will raise
    a RuntimeError while booting rather than run in an unsecurable environment.

    [GHSA-xr9x-r78c-5hrm]
    [CVE-2026-66066]

    Mike Dalessio

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • No changes.

Guides

  • No changes.

8.1.3

Choose a tag to compare

@jhawthorn jhawthorn released this 24 Mar 20:26

Active Support

  • Fix JSONGemCoderEncoder to correctly serialize custom object hash keys.

    When hash keys are custom objects whose as_json returns a Hash,
    the encoder now calls to_s on the original key object instead of
    on the as_json result.

    Before:
    hash = {CustomKey.new(123) => "value"}
    hash.to_json # => {"{:id=>123}":"value"}

    After:
    hash.to_json # => {"custom_123":"value"}

    Dan Sharp

  • Fix inflections to better handle overlapping acronyms.

    ActiveSupport::Inflector.inflections(:en) do |inflect|
      inflect.acronym "USD"
      inflect.acronym "USDC"
    end
    
    "USDC".underscore # => "usdc"

    Said Kaldybaev

  • Silence Dalli 4.0+ warning when using ActiveSupport::Cache::MemCacheStore.

    zzak

Active Model

  • Fix Ruby 4.0 delegator warning when calling inspect on attributes.

    Hammad Khan

  • Fix NoMethodError when deserialising Type::Integer objects marshalled under Rails 8.0.

    The performance optimisation that replaced @range with @max/@min
    broke Marshal compatibility. Objects serialised under 8.0 (with @range)
    and deserialised under 8.1 (expecting @max/@min) would crash with
    undefined method '<=' for nil because Marshal.load restores instance
    variables without calling initialize.

    Edward Woodcock

Active Record

  • Fix insert_all and upsert_all log message when called on anonymous classes.

    Gabriel Sobrinho

  • Respect ActiveRecord::SchemaDumper.ignore_tables when dumping SQLite virtual tables.

    Hans Schnedlitz

  • Restore previous instrumenter after execute_or_skip

    FutureResult#execute_or_skip replaces the thread's instrumenter with an
    EventBuffer to collect events published during async query execution.
    If the global async executor is saturated and the caller_runs fallback
    executes the task on the calling thread, we need to make sure the previous
    instrumenter is restored or the stale EventBuffer would stay in place and
    permanently swallow all subsequent sql.active_record notifications on
    that thread.

    Rosa Gutierrez

  • Bump the minimum PostgreSQL version to 9.5, due to usage of array_position function.

    Ivan Kuchin

  • Fix Ruby 4.0 delegator warning when calling inspect on ActiveRecord::Type::Serialized.

    Hammad Khan

  • Fix support for table names containing hyphens.

    Evgeniy Demin

  • Fix column deduplication for SQLite3 and PostgreSQL virtual (generated) columns.

    Column#== and Column#hash now account for virtual? so that the
    Deduplicable registry does not treat a generated column and a regular
    column with the same name and type as identical. Previously, if a
    generated column was registered first, a regular column on a different
    table could be deduplicated to the generated instance, silently
    excluding it from INSERT/UPDATE statements.

    Jay Huber

  • Fix PostgreSQL schema dumping to handle schema-qualified table names in foreign_key references that span different schemas.

    # before
    add_foreign_key "hst.event_log_attributes", "hst.event_logs" # emits correctly because they're in the same schema (hst)
    add_foreign_key "hst.event_log_attributes", "hst.usr.user_profiles", column: "created_by_id" # emits hst.user.* when user.* is expected
    
    # after
    add_foreign_key "hst.event_log_attributes", "hst.event_logs"
    add_foreign_key "hst.event_log_attributes", "usr.user_profiles", column: "created_by_id"
    

    Chiperific

Action View

  • Fix encoding errors for string locals containing non-ASCII characters.

    Kataoka Katsuki

  • Fix collection caching to only forward expires_in argument if explicitly set.

    Pieter Visser

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Fix ActiveStorage::Blob content type predicate methods to handle nil.

    Daichi KUDO

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • Add libvips to generated ci.yml

    Conditionally adds libvips to ci.yml.

    Steve Polito

Guides

  • No changes.

8.0.5

Choose a tag to compare

@jhawthorn jhawthorn released this 24 Mar 20:19

Active Support

  • Fix inflections to better handle overlapping acronyms.

    ActiveSupport::Inflector.inflections(:en) do |inflect|
      inflect.acronym "USD"
      inflect.acronym "USDC"
    end
    
    "USDC".underscore # => "usdc"

    Said Kaldybaev

  • Silence Dalli 4.0+ warning when using ActiveSupport::Cache::MemCacheStore.

    zzak

  • Make delegate and delegate_missing_to work in BasicObject subclasses.

    Rafael MendonΓ§a FranΓ§a

  • Fix ActiveSupport::Inflector.humanize with international characters.

    ActiveSupport::Inflector.humanize("Γ‘Γ‰ΓΓ“Γš")  # => "Áéíóú"
    ActiveSupport::Inflector.humanize("Π°Π‘Π’Π“Π”Π•") # => "АбвгдС"

    Jose Luis Duran

Active Model

  • No changes.

Active Record

  • Fix insert_all and upsert_all log message when called on anonymous classes.

    Gabriel Sobrinho

  • Respect ActiveRecord::SchemaDumper.ignore_tables when dumping SQLite virtual tables.

    Hans Schnedlitz

  • Restore previous instrumenter after execute_or_skip

    FutureResult#execute_or_skip replaces the thread's instrumenter with an
    EventBuffer to collect events published during async query execution.
    If the global async executor is saturated and the caller_runs fallback
    executes the task on the calling thread, we need to make sure the previous
    instrumenter is restored or the stale EventBuffer would stay in place and
    permanently swallow all subsequent sql.active_record notifications on
    that thread.

    Rosa Gutierrez

  • Fix Ruby 4.0 delegator warning when calling inspect on ActiveRecord::Type::Serialized.

    Hammad Khan

  • Fix support for table names containing hyphens.

    Evgeniy Demin

  • Fix column deduplication for SQLite3 and PostgreSQL virtual (generated) columns.

    Column#== and Column#hash now account for virtual? so that the
    Deduplicable registry does not treat a generated column and a regular
    column with the same name and type as identical. Previously, if a
    generated column was registered first, a regular column on a different
    table could be deduplicated to the generated instance, silently
    excluding it from INSERT/UPDATE statements.

    Jay Huber

  • Fix merging relations with arel equality predicates with null relations.

    fatkodima

  • Fix SQLite3 schema dump for non-autoincrement integer primary keys.

    Previously, schema.rb should incorrectly restore that table with an auto incrementing
    primary key.

    Chris HasiΕ„ski

  • Fix PostgreSQL schema_search_path not being reapplied after reset! or reconnect!.

    The schema_search_path configured in database.yml is now correctly
    reapplied instead of falling back to PostgreSQL defaults.

    Tobias Egli

  • Ensure batched preloaded associations accounts for klass when grouping to avoid issues with STI.

    zzak, Stjepan Hadjic

  • Fix ActiveRecord::SoleRecordExceeded#record to return the relation.

    This was the case until Rails 7.2, but starting from 8.0 it
    started mistakenly returning the model class.

    Jean Boussier

  • Improve PostgreSQLAdapter resilience to Timeout.timeout.

    Better handle asynchronous exceptions being thrown inside
    the reconnect! method.

    This may fixes some deep errors such as:

    undefined method `key?' for nil:NilClass (NoMethodError)
              if !type_map.key?(oid)
    

    Jean Boussier

  • Fix eager_load when loading has_many assocations with composite primary keys.

    This would result in some records being loaded multiple times.

    Martin-Alexander

Action View

  • Fix encoding errors for string locals containing non-ASCII characters.

    Kataoka Katsuki

  • Fix collection caching to only forward expires_in argument if explicitly set.

    Pieter Visser

  • Fix file_field to join mime types with a comma when provided as Array

    file_field(:article, :image, accept: ['image/png', 'image/gif', 'image/jpeg'])

    Now behaves likes:

    file_field(:article, :image, accept: 'image/png,image/gif,image/jpeg')
    

    Bogdan Gusiev

  • Fix strict locals parsing to handle multiline definitions.

    Said Kaldybaev

Action Pack

  • Add config.action_controller.live_streaming_excluded_keys to control execution state sharing in ActionController::Live.

    When using ActionController::Live, actions are executed in a separate thread that shares
    state from the parent thread. This new configuration allows applications to opt-out specific
    state keys that should not be shared.

    This is useful when streaming inside a connected_to block, where you may want
    the streaming thread to use its own database connection context.

    # config/application.rb
    config.action_controller.live_streaming_excluded_keys = [:active_record_connected_to_stack]

    By default, all keys are shared.

    Eileen M. Uchitelle

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Fix ActiveStorage::Blob content type predicate methods to handle nil.

    Daichi KUDO

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • Fixed the rails notes command to properly extract notes in CSS files.

    David White

  • Fixed the default Dockerfile to properly include the vendor/ directory during bundle install.

    Zhong Sheng

Guides

  • No changes.

8.1.2.1

Choose a tag to compare

@jhawthorn jhawthorn released this 23 Mar 19:42

Active Support

  • Reject scientific notation in NumberConverter

    [CVE-2026-33176]

    Jean Boussier

  • Fix SafeBuffer#% to preserve unsafe status

    [CVE-2026-33170]

    Jean Boussier

  • Improve performance of NumberToDelimitedConverter

    [CVE-2026-33169]

    Jean Boussier

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • Skip blank attribute names in tag helpers to avoid generating invalid HTML.

    [CVE-2026-33168]

    Mike Dalessio

Action Pack

  • Fix possible XSS in DebugExceptions middleware

    [CVE-2026-33167]

    John Hawthorn

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Filter user supplied metadata in DirectUploadController

    [CVE-2026-33173]

    Jean Boussier

  • Configurable maxmimum streaming chunk size

    Makes sure that byte ranges for blobs don't exceed 100mb by default.
    Content ranges that are too big can result in denial of service.

    [CVE-2026-33174]

    Gannon McGibbon

  • Limit range requests to a single range

    [CVE-2026-33658]

    Jean Boussier

  • Prevent path traversal in DiskService.

    DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".",
    ".."), or if the resolved path is outside the storage root directory.

    #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for
    example containing null bytes or having an incompatible encoding. Previously, the exception
    raised may have been ArgumentError or Encoding::CompatibilityError.

    DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes.

    [CVE-2026-33195]

    Mike Dalessio

  • Prevent glob injection in DiskService#delete_prefixed.

    Escape glob metacharacters in the resolved path before passing to Dir.glob.

    Note that this change breaks any existing code that is relying on delete_prefixed to expand
    glob metacharacters. This change presumes that is unintended behavior (as other storage services
    do not respect these metacharacters).

    [CVE-2026-33202]

    Mike Dalessio

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • No changes.

Guides

  • No changes.

8.0.4.1

Choose a tag to compare

@jhawthorn jhawthorn released this 23 Mar 19:38

Active Support

  • Reject scientific notation in NumberConverter

    [CVE-2026-33176]

    Jean Boussier

  • Fix SafeBuffer#% to preserve unsafe status

    [CVE-2026-33170]

    Jean Boussier

  • Improve performance of NumberToDelimitedConverter

    [CVE-2026-33169]

    Jean Boussier

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • Skip blank attribute names in tag helpers to avoid generating invalid HTML.

    [CVE-2026-33168]

    Mike Dalessio

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Filter user supplied metadata in DirectUploadController

    [CVE-2026-33173]

    Jean Boussier

  • Configurable maxmimum streaming chunk size

    Makes sure that byte ranges for blobs don't exceed 100mb by default.
    Content ranges that are too big can result in denial of service.

    [CVE-2026-33174]

    Gannon McGibbon

  • Limit range requests to a single range

    [CVE-2026-33658]

    Jean Boussier

  • Prevent path traversal in DiskService.

    DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".",
    ".."), or if the resolved path is outside the storage root directory.

    #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for
    example containing null bytes or having an incompatible encoding. Previously, the exception
    raised may have been ArgumentError or Encoding::CompatibilityError.

    DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes.

    [CVE-2026-33195]

    Mike Dalessio

  • Prevent glob injection in DiskService#delete_prefixed.

    Escape glob metacharacters in the resolved path before passing to Dir.glob.

    Note that this change breaks any existing code that is relying on delete_prefixed to expand
    glob metacharacters. This change presumes that is unintended behavior (as other storage services
    do not respect these metacharacters).

    [CVE-2026-33202]

    Mike Dalessio

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • No changes.

Guides

  • No changes.

7.2.3.1

Choose a tag to compare

@jhawthorn jhawthorn released this 23 Mar 19:32

Active Support

  • Reject scientific notation in NumberConverter

    [CVE-2026-33176]

    Jean Boussier

  • Fix SafeBuffer#% to preserve unsafe status

    [CVE-2026-33170]

    Jean Boussier

  • Improve performance of NumberToDelimitedConverter

    [CVE-2026-33169]

    Jean Boussier

Active Model

  • No changes.

Active Record

  • No changes.

Action View

  • Skip blank attribute names in tag helpers to avoid generating invalid HTML.

    [CVE-2026-33168]

    Mike Dalessio

Action Pack

  • No changes.

Active Job

  • No changes.

Action Mailer

  • No changes.

Action Cable

  • No changes.

Active Storage

  • Filter user supplied metadata in DirectUploadController

    [CVE-2026-33173]

    Jean Boussier

  • Configurable maxmimum streaming chunk size

    Makes sure that byte ranges for blobs don't exceed 100mb by default.
    Content ranges that are too big can result in denial of service.

    [CVE-2026-33174]

    Gannon McGibbon

  • Limit range requests to a single range

    [CVE-2026-33658]

    Jean Boussier

  • Prevent path traversal in DiskService.

    DiskService#path_for now raises an InvalidKeyError when passed keys with dot segments (".",
    ".."), or if the resolved path is outside the storage root directory.

    #path_for also now consistently raises InvalidKeyError if the key is invalid in any way, for
    example containing null bytes or having an incompatible encoding. Previously, the exception
    raised may have been ArgumentError or Encoding::CompatibilityError.

    DiskController now explicitly rescues InvalidKeyError with appropriate HTTP status codes.

    [CVE-2026-33195]

    Mike Dalessio

  • Prevent glob injection in DiskService#delete_prefixed.

    Escape glob metacharacters in the resolved path before passing to Dir.glob.

    Note that this change breaks any existing code that is relying on delete_prefixed to expand
    glob metacharacters. This change presumes that is unintended behavior (as other storage services
    do not respect these metacharacters).

    [CVE-2026-33202]

    Mike Dalessio

Action Mailbox

  • No changes.

Action Text

  • No changes.

Railties

  • No changes.

Guides

  • No changes.