//
sign in
Post
by @danabra.mov
PostEmbed
by @danabra.mov
Record
by @jimpick.com
Record
by @atsui.org
+ new component
Post
Hello Rubyist. Working hard all day is great, but maybe it's time to cool down. New in RubyGems/Bundler 4.0.13: blog.rubygems.org/2026/06/03/c...
13d
Most supply-chain attacks against RubyGems exploit a narrow window: an account is compromised, a malicious version ships, and any bundle install in the minutes that follow resolves straight to it. ...
blog.rubygems.org
Cool down before you install: give new gems a few days to be vetted
hsbt