Insights
Rails 8.0 security support ends 7 November 2026
Published 8 October 2026 · Dates checked against the official Rails and Ruby maintenance pages on that day
On 7 November 2026 the Rails 8.0 series stops receiving security fixes. After that date only Rails 8.1 is supported. Every Rails series before 8.0 — including 7.2, 7.1, and anything in the 6.x or 5.x lines — already receives no fixes of any kind.
If your business runs on a Rails app, this is the moment to check which version it is on, because “it still works” and “it still gets security patches” are no longer the same thing for most Rails apps in production.
Rails: what is supported today
Rails gives each minor series one year of bug fixes and two years of security fixes from its first release.
| Series | Bug fixes until | Security fixes until | Status |
|---|---|---|---|
| 8.1 | 10 Oct 2026 | 10 Oct 2027 | Supported |
| 8.0 | 7 May 2026 (ended) | 7 Nov 2026 | Security fixes only |
| 7.2 and older | Ended | Ended | Unsupported |
Ruby: the other half of the question
The Ruby version your app runs on has its own support window, and it matters just as much: an unsupported Ruby receives no security fixes regardless of your Rails version. Rails 8 also requires Ruby 3.2 or newer, so the Ruby upgrade is often the first step.
| Ruby | Status | End of life |
|---|---|---|
| 4.0 | Normal maintenance | Not yet announced |
| 3.4 | Normal maintenance | Not yet announced |
| 3.3 | Security maintenance | 31 Mar 2027 (expected) |
| 3.2 | End of life | 1 Apr 2026 |
| 3.1 and older | End of life | Ended |
What “end of support” means in practice
- When a vulnerability is found in an unsupported series, no patched release is published for it. The fix exists only in newer versions.
- Gems gradually drop support for old Rails and Ruby versions, so even small dependency updates start to require a framework upgrade first.
- Security questionnaires, payment-provider reviews, and audits increasingly ask which framework versions you run and whether they are supported.
None of this breaks your app on 8 November. It means the cost of staying put grows quietly, and the upgrade gets longer the later it starts.
Where you are, and what to do
- On Rails 8.0: the move to 8.1 is a single minor-version step. Plan it before 7 November, and check your Ruby version at the same time.
- On Rails 7.x: you are already outside security support. The path is one minor version at a time — 7.0 → 7.1 → 7.2 → 8.0 → 8.1 — with Ruby moved to a supported version along the way.
- On Rails 6.x or older: the same path, with more steps. Start by pinning your most important flows with tests, because each later step is only as safe as the evidence that nothing broke.
Whatever the starting point, the safest approach is staged: small steps on the main branch, each one shipped to production and reversible on its own, rather than a long-lived upgrade branch or a rewrite. We have written that approach out in full as a Rails upgrade reference design.
Find out where your app stands
The Rails App Audit checks your Rails, Ruby, and gem versions against their support status, identifies what blocks an upgrade, and gives you a staged, priced plan you keep either way. See what the report looks like.