Rails main requires Ruby 3.3.5 and drops dynamic :controller routes
Two changes merged into Rails' main branch this week will matter to applications when the next major release ships, the project's weekly summary reports. One raises the floor for Ruby; the other removes a routing style that has been deprecated since Rails 5.0.
Ruby 3.3.5 becomes the minimum. Pull request 58908, merged on 1 October, explains the reason. Ruby versions before 3.3.5 carry a use-after-free bug in their WeakMap and WeakKeyMap implementation, which the author describes as previously judged easy to hit. Because of it, Rails had been using a stricter polyfill that only accepts keys such as threads and fibers. The author's application was spending noticeable CPU on clearing the query cache, because the current code walks every connection pool to clear the cache for the current execution context. Inverting that structure, so that only the pools actually used in a context are visited, needs connection pools as weak keys, which the polyfill forbids. The bump makes that refactor possible; a follow-up pull request already removes code kept for older Rubies.
Routes can no longer take the controller or action from the URL. Pull request 58893 by Aaron Patterson, merged on 30 September, makes a route such as get ":controller(/:action(/:id))" raise an ArgumentError when drawn. The changelog tells applications to write out the routes they serve instead, for example get "photos", to: "photos#index". Two related patterns break too: passing a controller class without an action, as in get "show", to: PhotosController, now needs action: "show", and a regular expression for :controller or :action raises instead of drawing a route that could never match. Request#controller_class now raises ActionDispatch::MissingController when there is no :controller parameter, for example before routing or for requests handed to a Rack endpoint, instead of returning a placeholder that answered with a 404.
The summary also notes that the Rails World talks are on YouTube, that a rewritten guide on autoloading and reloading is open for review, and that an except_on option now sits alongside on in the validation callback options. Thirty-four people contributed during the week.

What it means
Neither change is in a released version yet, which is the point of reading main: there is time. Applications still running Ruby 3.2 or early 3.3 releases have a concrete date to plan against, and a quick search for :controller in config/routes.rb tells a team now whether an old catch-all route will stop the application from booting.