Guide · Ruby on RailsUpdated September 29, 2026
Rails 8.0 end of life: the dates and the upgrade to 8.1
Rails 8.0 no longer gets bug fixes, and its security fixes stop on November 7, 2026. After that date a Rails security advisory brings no 8.0 release. This guide lists the official dates, the Ruby versions Rails needs, what Rails 8.1 removes and deprecates, and the order we upgrade in.
The dates
From the Rails maintenance policy and release posts, checked on September 29, 2026.
- Rails 8.0 bug fixes
- Ended May 7, 2026. Ruby on Rails: Maintenance policy
- Rails 8.0 security fixes
- End November 7, 2026. After that, the 8.0 series is at end of life. Ruby on Rails: Maintenance policy
- Rails 8.1 bug fixes
- Until October 10, 2026. Ruby on Rails: Maintenance policy
- Rails 8.1 security fixes
- Until October 10, 2027. Ruby on Rails: Maintenance policy
- Rails 7.2
- Reached end of life with 7.2.4 on September 24, 2026: “Security issues and bug fixes will only be provided for the 8.0.x and 8.1.x series.” Ruby on Rails blog: Rails version 7.2.4 has been released
- Latest releases
- 8.1.4 on September 24, 2026. The latest 8.0 release is 8.0.5.1, a security release on July 29, 2026. Ruby on Rails blog: Rails version 8.1.4 has been released
What end of life means for a Rails app
The Rails maintenance policy gives each minor release series one year of bug fixes and two years of security fixes, counted from the first release in the series. Rails 8.0 is in the second year now: only security releases, and only “direct security patches” go into them.
Once the security window closes, the policy is explicit: “it’s your own responsibility to deal with bugs and security issues. We may provide backports of the fixes and publish them to git, however there will be no new versions released.” The last 8.0 release, 8.0.5.1, fixed CVE-2026-66066, a possible arbitrary file read and remote code execution in Active Storage variant processing. A fix like that after November 7, 2026 would ship for 8.1 only.
Who is affected
Every app on Rails 8.0.x. Apps on 7.2 or older are already past end of life, because 7.2.4 was the last release of that series; they need to move through 8.0 to 8.1, since the Rails 8.1 release notes ask you to “first upgrade to Rails 8.0” before attempting 8.1.
The risk is not that the app stops working on November 8. It keeps running. The risk is the next advisory: without a patched gem to install, the choice is between backporting the fix yourself and doing the upgrade under time pressure.
Ruby versions
“Rails 8.0 and 8.1 require Ruby 3.2.0 or newer.” The minimum is itself past end of life, so an upgrade is also the moment to move Ruby.
| Ruby | Status | End of life |
|---|---|---|
| 3.2 | End of life | April 1, 2026 |
| 3.3 | Security maintenance | March 31, 2027 (expected) |
| 3.4 | Normal maintenance | Not set |
| 4.0 | Normal maintenance | Not set |
Ruby status from ruby-lang.org; the Ruby requirement from the Rails upgrading guide. Rails does not name a recommended version; its guide says to “upgrade to the latest Ruby you can first, and then upgrade Rails.”
What Rails 8.1 removes and deprecates
The upgrading guide has a single item for 8.0 to 8.1. The rest comes from the 8.1 release notes; these are the ones most likely to touch an existing app.
schema.rb column order
Table columns inside schema.rb are now sorted alphabetically, so dumps stay the same across machines. Expect one large, harmless diff on the first migration after the upgrade; structure.sql still keeps exact column order.
Finders without an order
Order-dependent finder methods such as #first on a relation without an order are deprecated. Add an explicit order wherever the result depends on it.
Query strings and routes
Semicolons as a query string separator are removed, as is a route pointing to multiple paths and the skipping of leading brackets in parameter names.
Active Job and Sidekiq
The built-in Sidekiq adapter is deprecated, because the adapter now ships with the sidekiq gem. The old enqueue_after_transaction_commit values and setting are removed, and so is the SuckerPunch adapter.
Active Support
Benchmark.ms is removed (it lives in the benchmark gem), to_time always preserves the receiver’s timezone, and String#mb_chars and ActiveSupport::Configurable are deprecated.
Storage and databases
The :azure Active Storage service is removed, along with the SQLite3 :retries option and the MySQL unsigned_float and unsigned_decimal types. bin/rake stats is gone too.
What an 8.0 to 8.1 upgrade involves
The order follows the Rails upgrading guide: one minor version at a time, with the tests and deprecation warnings doing the work.
1. Tests first
“The best way to be sure that your application still works after upgrading is to have good test coverage before you start the process.” Where coverage is thin, add request or contract tests for the paths the business depends on before touching versions.
2. Latest 8.0 patch and zero deprecations
Move to the latest 8.0 patch, run the suite with deprecation warnings visible, and fix them. Every warning you clear on 8.0 is one less failure on 8.1.
3. Ruby
If the app is still on Ruby 3.2, move Ruby first and ship that on its own, so a failure points at one change.
4. Gems
Change the Rails version in the Gemfile and run bundle update rails. Gems that pin Rails, Active Job adapters and anything patching Active Record are the usual blockers.
5. bin/rails app:update
Run the update task and review each change it proposes to config files. It also creates config/initializers/new_framework_defaults_8_1.rb.
6. New defaults, gradually
Enable the new defaults in that file one by one, “gradually over several deployments”. When all are on, delete the file and set config.load_defaults 8.1.
7. A deploy you can roll back
Ship the version bump with the old defaults first, keep migrations backward compatible with the running code, and watch errors and job queues after each step. That keeps the upgrade to deploys users do not notice.
Rails 8.1 upgrade checklist
- Note the current Rails, Ruby and Bundler versions and the date the upgrade has to be live by: November 7, 2026.
- Test suite green on the latest 8.0 patch, with deprecation warnings on and none left.
- Ruby on a maintained version (3.3 or newer) and deployed on its own.
- Gemfile updated, bundle update rails clean, no gem pinned below 8.1.
- Sidekiq and other Active Job adapters on versions that provide their own adapter.
- Explicit order on relations that use first or last where the result matters.
- bin/rails app:update run and every config diff reviewed.
- new_framework_defaults_8_1.rb enabled step by step, then config.load_defaults 8.1.
- schema.rb regenerated and the column-order diff committed on its own.
- Staging deploy, error tracking and job queues watched, then production.
What you get with Rails 8.1
Rails 8.1 was released on October 22, 2025. The headline features from the release post:
Active Job continuations
Long-running jobs are split into steps and resume from the last completed step after a restart.
Structured events
Rails.event.notify gives one interface for structured events that monitoring can consume.
Local CI
A CI declaration in config/ci.rb, run with bin/ci.
Deprecated associations
Mark an association deprecated: true and Rails warns, raises or notifies wherever it is still used.
Timeline
- 2025-10-22
Rails 8.1 released
Job continuations, structured events and local CI.
- 2026-05-07
Rails 8.0 bug fixes end
From here, 8.0 gets security releases only.
- 2026-07-29
Rails 8.0.5.1
Security release for CVE-2026-66066 in Active Storage.
- 2026-09-24
Rails 7.2 end of life, Rails 8.1.4
7.2.4 is the last 7.2 release.
- 2026-10-10
Rails 8.1 bug fixes end
8.1 continues with security releases until October 10, 2027.
- 2026-11-07
Rails 8.0 end of life
No more 8.0 releases, including security fixes.
Questions about Rails 8.0 end of life
When does Rails 8.0 reach end of life?
November 7, 2026, when its security fixes end. Bug fixes already ended on May 7, 2026.
Will my app stop working after November 7, 2026?
No. It keeps running. What stops is new 8.0 releases, so a future security advisory will not come with a patched 8.0 gem.
How long is Rails 8.1 supported?
Bug fixes until October 10, 2026 and security fixes until October 10, 2027, according to the Rails maintenance policy.
Which Ruby version do I need for Rails 8.1?
Ruby 3.2.0 or newer. Ruby 3.2 itself reached end of life on April 1, 2026, so a maintained Ruby (3.3, 3.4 or 4.0) is the sensible target.
We are on Rails 7.2. Can we jump straight to 8.1?
The Rails 8.1 release notes say to upgrade to 8.0 first, and the upgrading guide recommends one minor version at a time. Both steps can ship within one project, as separate deploys.
How long does an 8.0 to 8.1 upgrade take?
It depends on test coverage, the number of gems that pin Rails and how many deprecation warnings the app has today. A code audit gives you that number before you commit to it.
Next step
30 minutes with an engineer, not a sales rep. You leave knowing what we'd fix first — or that you don't need us.
The first call is free. A code audit of your Rails app is a fixed price from $750, credited against the upgrade if you continue within 30 days. A Rails 8.0 to 8.1 upgrade is a fixed price from $1,200.
Sources
- Ruby on Rails: Maintenance policy
- Rails Guides: Maintenance policy for Ruby on Rails
- Rails Guides: Upgrading Ruby on Rails
- Rails Guides: Ruby on Rails 8.1 release notes
- Ruby on Rails blog: Rails 8.1 — job continuations, structured events, local CI
- Ruby on Rails blog: Rails versions 7.2.3.2, 8.0.5.1 and 8.1.3.1 have been released
- Ruby on Rails blog: Rails version 8.1.4 has been released
- Ruby on Rails blog: Rails version 7.2.4 has been released
- ruby-lang.org: Ruby maintenance branches
Checked September 29, 2026.