Httponly cookies in Rails
Why and how, for session and normal cookies
Why and how, for session and normal cookies
Keep your gems and RubyGems sources safe
Using another language doesn’t fix XSS
2 processes updating a record may have unexpected results
A distributed layer-7 (http) attack
Paperclip gem security update
A vulnerable Rails app that follows the OWASP Top 10
Bundler-audit checks for vulnerable versions of your gems
Announcements by e-mail
The most critical web application security flaws