August 21, 2006
Filtered parameter logging
Now that the hubbub about the recent security issues has died down, I think it’s worth pointing out a little jewel that was snuck into the 1.1.6 security release of...
August 20, 2006
Trac and SVN gets new powerful machine
After an extended period of troublesome Trac times, we’ve finally addressed the problem once and for all. Courtesy of TextDrive, we now have a new mega-powerful super machine dedicated to...
August 18, 2006
Official Mailing List Move
Don’t worry if you see some mailing list subscriptions in your inbox, we’re simply transferring everything to Google Groups. This takes the incredible load off the Ruby on Rails server...
August 16, 2006
Streamlined: Taking admins beyond scaffolding
Justin Gehtland and Stuart Halloway has been moving along at a rapid pace on Streamlined since its unveiling at RailsConf in June. There’s now a public repository with the code...
August 14, 2006
Recent Rails job postings from the Job Board
We’re going to start posting a summary of recent Rails job postings from the 37signals Job Board every few weeks. All of these positions are for Rails programmers, but be...
August 11, 2006
Reloading Revamped
A few days ago I checked in a significant improvement to Rails’ dependencies and reloading code. In the past, changes to dependencies.rb have shed the blood of those courageous enough...
August 10, 2006
New dedicated Trac server on the way
Our current web and mail server has been buckling under the load of the recent frenzy. Especially Trac and mailman is taking it to its knees. So we’re going to...
August 10, 2006
New security mailing list
In light of the past days of fun and games, we’ve started a new mailing list focused entirely around security. This list will be much lower volume than the main...
August 10, 2006
Rails 1.1.6, backports, and full disclosure
The cat is out of the bag, so here’s the full disclosure edition of the current security vulnerability. With Rails 1.1.0 through 1.1.5 (minus the short-lived 1.1.3), you can trigger...
August 10, 2006
Security update: Rails 1.0, 1.1.3 not affected
Good news: Rails 1.0 and prior is not affected by the latest security breach we’ve experienced. Neither is Rails 1.1.3. We’re currently investigating further just how contaminated 1.1.0, 1.1.1, 1.1.2,...