The go-to resource for upgrading Ruby, Rails, and your dependencies.
An in-depth look at CVE-2008-3905, where predictable transaction IDs and source ports in Ruby's resolv.rb allowed DNS spoofing attacks.
Mar 15, 2026