//
sign in
Post
by @danabra.mov
PostEmbed
by @danabra.mov
Record
by @jimpick.com
Record
by @atsui.org
+ new component
Post
Important development for the #Ruby ecosystem blog.rubygems.org/2026/06/03/c... One also has to wonder how come supply-chain attacks became so much more common and devastating in recent months... ;-)
13d
Most supply-chain attacks against RubyGems exploit a narrow window: an account is compromised, a malicious version ships, and any bundle install in the minutes that follow resolves straight to it. ...
blog.rubygems.org
Cool down before you install: give new gems a few days to be vetted
Bozhidar Batsov (a.k.a. Bug)