zlacker

[return to "Ruby Central's Attack on RubyGems [pdf]"]
1. thomas+pH[view] [source] 2025-09-19 14:09:26
>>jolux+(OP)
An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler

https://rubycentral.org/news/strengthening-the-stewardship-o...

◧◩
2. coryth+jN[view] [source] 2025-09-19 14:44:00
>>thomas+pH
Aren’t supply chain attacks caused by package maintainer accounts being compromised? I suppose too many people with keys to the package repository itself is also liability, but those accounts being compromised just hasn’t been what is happening.
◧◩◪
3. coryth+O57[view] [source] 2025-09-21 20:41:47
>>coryth+jN
The other side of the story came out, and of course, it’s very reasonable https://apiguy.substack.com/p/a-board-members-perspective-of...
[go to top]