How to Efficiently Patch a Ruby on Rails Application When a Critical CVE Drops
A walkthrough of efficiently patching a Ruby on Rails application when a critical CVE drops, using CVE-2022-32224 (an ActiveRecord vulnerability affecting YAML-serialized fields) as the working example. The principles apply broadly, well beyond that one CVE. Recorded at the monthly Atlanta Ruby Users’ Group (ATLRUG) meeting on July 13, 2022.