Skip to content
Veldway

Insights

Rails 8.0 security support ends 7 November 2026

Published 8 October 2026 · Dates checked against the official Rails and Ruby maintenance pages on that day

On 7 November 2026 the Rails 8.0 series stops receiving security fixes. After that date only Rails 8.1 is supported. Every Rails series before 8.0 — including 7.2, 7.1, and anything in the 6.x or 5.x lines — already receives no fixes of any kind.

If your business runs on a Rails app, this is the moment to check which version it is on, because “it still works” and “it still gets security patches” are no longer the same thing for most Rails apps in production.

Rails: what is supported today

Rails gives each minor series one year of bug fixes and two years of security fixes from its first release.

SeriesBug fixes untilSecurity fixes untilStatus
8.110 Oct 202610 Oct 2027Supported
8.07 May 2026 (ended)7 Nov 2026Security fixes only
7.2 and olderEndedEndedUnsupported

Ruby: the other half of the question

The Ruby version your app runs on has its own support window, and it matters just as much: an unsupported Ruby receives no security fixes regardless of your Rails version. Rails 8 also requires Ruby 3.2 or newer, so the Ruby upgrade is often the first step.

RubyStatusEnd of life
4.0Normal maintenanceNot yet announced
3.4Normal maintenanceNot yet announced
3.3Security maintenance31 Mar 2027 (expected)
3.2End of life1 Apr 2026
3.1 and olderEnd of lifeEnded

What “end of support” means in practice

  • When a vulnerability is found in an unsupported series, no patched release is published for it. The fix exists only in newer versions.
  • Gems gradually drop support for old Rails and Ruby versions, so even small dependency updates start to require a framework upgrade first.
  • Security questionnaires, payment-provider reviews, and audits increasingly ask which framework versions you run and whether they are supported.

None of this breaks your app on 8 November. It means the cost of staying put grows quietly, and the upgrade gets longer the later it starts.

Where you are, and what to do

  • On Rails 8.0: the move to 8.1 is a single minor-version step. Plan it before 7 November, and check your Ruby version at the same time.
  • On Rails 7.x: you are already outside security support. The path is one minor version at a time — 7.0 → 7.1 → 7.2 → 8.0 → 8.1 — with Ruby moved to a supported version along the way.
  • On Rails 6.x or older: the same path, with more steps. Start by pinning your most important flows with tests, because each later step is only as safe as the evidence that nothing broke.

Whatever the starting point, the safest approach is staged: small steps on the main branch, each one shipped to production and reversible on its own, rather than a long-lived upgrade branch or a rewrite. We have written that approach out in full as a Rails upgrade reference design.

Find out where your app stands

The Rails App Audit checks your Rails, Ruby, and gem versions against their support status, identifies what blocks an upgrade, and gives you a staged, priced plan you keep either way. See what the report looks like.

Sources

Is your Rails app on a supported version?

Describe the problem in plain language — broken, slow, manual, or missing. We'll tell you honestly whether and how we can help.

  1. 01We reply within one business day
  2. 02A short call to understand the problem
  3. 03A written scope and fixed quote — no obligation