ruby-growl icon indicating copy to clipboard operation
ruby-growl copied to clipboard

vulnerability for gems with dashes

Open reedhein opened this issue 8 years ago • 2 comments

http://blog.rubygems.org/2016/04/06/gem-replacement-vulnerability-and-mitigation.html

reedhein avatar Jun 01 '16 22:06 reedhein

Did you find the latest tag doesn't match the .gem file?

drbrain avatar Jun 01 '16 22:06 drbrain

I haven't checked it out. I heard it on ruby5 and remembered the issue with the matching the gem name (blank-dash-blank). The last file update falls within the timeframe of the article. Because of the reasons outlined, I put it up as an issue. I cannot say whether or not it's a problem. I will follow up tonight or tomorrow.

reedhein avatar Jun 01 '16 22:06 reedhein