Generally: don't trust anything from the outside world or anything that can transit untrusted infrastructure, that means check types and sanitize values before passing along. Break loudly and quickly to get attention for a fix. Keep the codebase as tiny as possible too.
Ruby: recompile with minimized OpenSSL 1.0.1+ (LibreSSL when possible) and with patches that improve Ruby's default OpenSSL security.
https://gist.github.com/steakknife/8228264
https://gist.github.com/steakknife/10092587
https://gist.github.com/steakknife/10096008
For Rails apps: use brakeman as one part of security audit strategy
For gem authors, sign them (please!): I wrote waxseal to make it dead simple
[sudo] gem cert --add <(curl -L https://gist.github.com/steakknife/5333881/raw/gem-public_cert.pem) # adds my cert (do once)
[sudo] gem install waxseal --trust-policy HighSecurity
For gem users, find which aren't signed Add this to ~/.gemrc gem line:
--trust-policy MediumSecurity
or just if there's no gem: .... already:
gem: --trust-policy MediumSecurity
For anyone using git, sign your tags (git tag -s ...) and commits (git commit -S ...) por favor