はてなブックマークアプリ

サクサク読めて、
アプリ限定の機能も多数!

アプリで開く

はてなブックマーク

  • はてなブックマークって?
  • アプリ・拡張の紹介
  • ユーザー登録
  • ログイン
  • Hatena

はてなブックマーク

トップへ戻る

  • 総合
    • 人気
    • 新着
    • IT
    • 最新ガジェット
    • 自然科学
    • 経済・金融
    • おもしろ
    • マンガ
    • ゲーム
    • はてなブログ(総合)
  • 一般
    • 人気
    • 新着
    • 社会ニュース
    • 地域
    • 国際
    • 天気
    • グルメ
    • 映画・音楽
    • スポーツ
    • はてな匿名ダイアリー
    • はてなブログ(一般)
  • 世の中
    • 人気
    • 新着
    • 新型コロナウイルス
    • 働き方
    • 生き方
    • 地域
    • 医療・ヘルス
    • 教育
    • はてな匿名ダイアリー
    • はてなブログ(世の中)
  • 政治と経済
    • 人気
    • 新着
    • 政治
    • 経済・金融
    • 企業
    • 仕事・就職
    • マーケット
    • 国際
    • はてなブログ(政治と経済)
  • 暮らし
    • 人気
    • 新着
    • カルチャー・ライフスタイル
    • ファッション
    • 運動・エクササイズ
    • 結婚・子育て
    • 住まい
    • グルメ
    • 相続
    • はてなブログ(暮らし)
    • 掃除・整理整頓
    • 雑貨
    • 買ってよかったもの
    • 旅行
    • アウトドア
    • 趣味
  • 学び
    • 人気
    • 新着
    • 人文科学
    • 社会科学
    • 自然科学
    • 語学
    • ビジネス・経営学
    • デザイン
    • 法律
    • 本・書評
    • 将棋・囲碁
    • はてなブログ(学び)
  • テクノロジー
    • 人気
    • 新着
    • IT
    • セキュリティ技術
    • はてなブログ(テクノロジー)
    • AI・機械学習
    • プログラミング
    • エンジニア
  • おもしろ
    • 人気
    • 新着
    • まとめ
    • ネタ
    • おもしろ
    • これはすごい
    • かわいい
    • 雑学
    • 癒やし
    • はてなブログ(おもしろ)
  • エンタメ
    • 人気
    • 新着
    • スポーツ
    • 映画
    • 音楽
    • アイドル
    • 芸能
    • お笑い
    • サッカー
    • 話題の動画
    • はてなブログ(エンタメ)
  • アニメとゲーム
    • 人気
    • 新着
    • マンガ
    • Webマンガ
    • ゲーム
    • 任天堂
    • PlayStation
    • アニメ
    • バーチャルYouTuber
    • オタクカルチャー
    • はてなブログ(アニメとゲーム)
    • はてなブログ(ゲーム)
  • おすすめ

    GWの過ごし方

『RubyGems Blog - RubyGems Blog』

  • 人気
  • 新着
  • すべて
  • How RubyGems.org Protects Our Community’s Critical OSS Infrastructure - RubyGems Blog

    3 users

    blog.rubygems.org

    Recently, Socket.dev published research highlighting malicious gems designed to steal social media credentials. We wanted to use this as an opportunity to share more about how RubyGems.org security operates, how we proactively handled this incident (and others), and the work our team is doing each day to keep the ecosystem safe. How We Detect Malicious Gems RubyGems.org security uses a proactive a

    • テクノロジー
    • 2025/09/01 20:07
    • Ruby
    • Security
    • Bundler v2.7: last release before Bundler 4 - RubyGems Blog

      5 users

      blog.rubygems.org

      Back to blog posts 17 Jul 2025 Bundler v2.7: last release before Bundler 4 by David Rodríguez A major release of Bundler is finally happening, consolidating unreleased major changes that had been pending for a decade. It will be named Bundler 4 (skipping Bundler 3), so that we can release it in lockstep with RubyGems 4, making the version number of Bundler & RubyGems in sync from now on. Final Bun

      • テクノロジー
      • 2025/07/18 05:35
      • ruby
      • Introducing New Policies for RubyGems.org - RubyGems Blog

        3 users

        blog.rubygems.org

        We’re pleased to introduce several key policies for RubyGems.org for community review. These include a Terms of Service, Privacy Notice, Acceptable Use Policy, and Copyright Policy. While these policies align with how RubyGems has always operated, the absence of formal documentation created ambiguity around acceptable use. These new policies provide clarity and transparency regarding our operation

        • テクノロジー
        • 2025/06/03 15:28
        • ruby
        • Bundler Auto-Install Just Got A Whole Lot Better - RubyGems Blog

          9 users

          blog.rubygems.org

          The RubyGems Team is happy to share this post from our colleague Ngan Pham, Principle Software Engineer @ Gusto. Thank you, Ngan! Working in a large monolith with many engineers, you never fail to get a flurry of changes everytime you pull from main. Then you have the typical ritual of running bundle install and, if you’re on a Rails application, rails db:prepare. Sometimes, you forget to run bund

          • テクノロジー
          • 2024/05/31 10:38
          • ruby
          • あとで読む
          • Announcing Trusted Publishing on RubyGems.org - RubyGems Blog

            10 users

            blog.rubygems.org

            Hi all! I’m excited to share a new feature that will help make RubyGems.org more secure, as well as making it easier to automate gem publishing. Inspired by the Python package index, we’re calling it Trusted Publishing. Backstory Over the past few years, we’ve increased the minimum multi-factor authentication (MFA) requirements for accounts that own popular gems. We highly encourage requiring MFA

            • テクノロジー
            • 2023/12/14 16:14
            • ruby
            • Making popular Ruby packages more secure - RubyGems Blog

              7 users

              blog.rubygems.org

              Attacks on the software supply chain are increasing and our community has not gone unscathed. RubyGems has been affected by supply chain attacks in the past, so it’s important for us to mitigate these risks as much as possible. Recommending stronger security practices like enabling multi-factor authentication (MFA) on popular packages is a first step towards improving the security of the RubyGems

              • テクノロジー
              • 2022/06/14 07:21
              • Ruby
              • security
              • あとで読む
              • Announcing RubyGems.org Stats - RubyGems Blog

                3 users

                blog.rubygems.org

                Ever since it was first released, the Bundler team has wanted to know more about the developers out there using our code. What versions of Ruby are still being actively used? What versions of RubyGems is it safe to stop supporting? Which operating systems should we focus on testing? It’s been almost 10 years since that first release, but today the RubyGems and Bundler team is excited to announce t

                • テクノロジー
                • 2020/03/17 05:40
                • ruby
                • March 2019 Security Advisories

                  4 users

                  blog.rubygems.org

                  Today we’re disclosing several vulnerablities to RubyGems. They have all been reported via hackerone. We strongly recommend to upgrade the latest stable version of RubyGems 3.0.3 or 2.7.8. If you can’t upgrade RubyGems 2.7 or 3.0, please use this patch for RubyGems 2.6. CVE-2019-8320: Delete directory using symlink when decompressing tar Description A Directory Traversal issue was discovered in Ru

                  • テクノロジー
                  • 2019/03/05 09:32
                  • security
                  • Ruby
                  • あとで読む
                  • Bundler 1.16: 2.0 Is So Close! - RubyGems Blog

                    5 users

                    blog.rubygems.org

                    Back to blog posts 31 Oct 2017 Bundler 1.16: 2.0 Is So Close! by Samuel Giddins What’s new in Bundler 1.16? A short summer after the performance-focused Bundler 1.15 release, we’ve shipped 1.16. Before we get to the list of changes, we want to share a very exciting announcement: Bundler 2.0 is right around the corner! We anticipate that v1.16 will be the last 1.x release, and details about the tra

                    • テクノロジー
                    • 2017/11/03 14:35
                    • Unsafe Object Deserialization Vulnerability in RubyGems

                      6 users

                      blog.rubygems.org

                      Hello everyone! An unsafe object deserialization vulnerability was found in RubyGems. Unfortunately this vulnerability can be used as a way to escalate to a remote code execution exploit. The good news is that this issue was responsibly reported to the RubyGems team by Max Justicz, and we were able to promptly fix it. The RubyGems team audited all Gems, and using the data available to us we can sa

                      • テクノロジー
                      • 2017/10/10 12:33
                      • ruby
                      • security
                      • 2.6.13 Released

                        7 users

                        blog.rubygems.org

                        RubyGems 2.6.13 includes security fixes. To update to the latest RubyGems you can run: If you need to upgrade or downgrade please follow the how to upgrade/downgrade RubyGems instructions. To install RubyGems by hand see the Download RubyGems page. Security fixes: Fix a DNS request hijacking vulnerability. Discovered by Jonathan Claudius, fix by Samuel Giddins. (CVE-2017-0902) Fix an ANSI escape s

                        • 学び
                        • 2017/08/30 05:02
                        • Bundler 1.15: Bundle Oh So Fast - RubyGems Blog

                          3 users

                          blog.rubygems.org

                          Back to blog posts 19 May 2017 Bundler 1.15: Bundle Oh So Fast by Samuel Giddins What’s new in Bundler 1.15? Hot on the heels of the many small fixes in Bundler 1.14, we’re pushing out 1.15. The list of changes is much shorter, but we think you’re going to love it all the same, since this time around we’ve focused on making Bundler a whole heck of a lot faster. Speed Due to Julian Nadeau’s prompti

                          • テクノロジー
                          • 2017/05/26 13:13
                          • ruby
                          • Funding Rubygems.org

                            5 users

                            blog.rubygems.org

                            Since the early days of Ruby, Ruby Central, Inc. has served as an organizational anchor for our community. Starting in 2001, with the organization of the first International Ruby Conference, we have been responsible for running RubyConf and subsequently RailsConf. Thanks to you all, our conferences have enjoyed broad, sustainable success, endowing us with a solid financial foundation, which we the

                            • テクノロジー
                            • 2017/03/16 09:30
                            • RubyGems
                            • Ruby
                            • RubyGems.org gem replacement vulnerability and mitigation

                              54 users

                              blog.rubygems.org

                              Summary RubyGems.org contained a bug that could allow an attacker to replace some .gem files on our servers with a different file that they supplied. We deployed a partial fix on April 2nd and a complete fix on April 4th, 2016. We also verified every .gem uploaded after Feb 8th, 2015, and found that none of them had been replaced. Gems whose name contains a dash (e.g. ‘blank-blank’) uploaded befor

                              • テクノロジー
                              • 2016/04/07 07:30
                              • rubygems
                              • ruby
                              • security
                              • gem
                              • セキュリティ
                              • あとで読む
                              • CVE-2015-3900 Request hijacking vulnerability in RubyGems 2.4.6 and earlier

                                7 users

                                blog.rubygems.org

                                CVE-2015-3900 Request hijacking vulnerability in RubyGems 2.4.6 and earlier RubyGems provides the ability of a domain to direct clients to a separate host that is used to fetch gems and make API calls against. This mechanism is implemented via DNS, specificly a SRV record _rubygems._tcp under the original requested domain. For example, this is the one that users who use rubygems.org see: > dig _ru

                                • テクノロジー
                                • 2015/06/25 21:06
                                • Ruby
                                • security
                                • セキュリティ
                                • Version 1.10 released - RubyGems Blog

                                  4 users

                                  blog.rubygems.org

                                  Bundler 1.10 is out! In fact, Bundler 1.10.5 is out today, so we thought it was high time to let everyone know about it. This release comes with a bunch of new features: the lock command, support for inline gemfiles in scripts, the ability to disable post-install messages, optional groups, conditional gem installation, dramatically improved outdated output, and the option to force installed gems t

                                  • テクノロジー
                                  • 2015/06/25 08:59
                                  • Bundler template moves bins to exe - RubyGems Blog

                                    4 users

                                    blog.rubygems.org

                                    Back to blog posts 20 Mar 2015 Bundler template moves bins to exe by Benjamin Fleischer - spec.executables = spec.files.grep(%r{^bin/}) { |f| File.basename(f) } + spec.executables = spec.files.grep(%r{^exe/}) { |f| File.basename(f) } This means that the Bundler-generated gems can use and commit binstubs, such as bin/rake, to the bin/ directory. Only files in the exe/ directory will be built with t

                                    • テクノロジー
                                    • 2015/04/13 10:58
                                    • bundler
                                    • ruby
                                    • Bundler may install gems from a different source than expected (CVE-2013-0334) - RubyGems Blog

                                      6 users

                                      blog.rubygems.org

                                      Back to blog posts 14 Aug 2014 Bundler may install gems from a different source than expected (CVE-2013-0334) by André Arko Versions Affected: All versions < 1.7.0 Not Affected: Any Gemfile with one or zero sources Fixed Versions: 1.7.0 Releases: 1.7.0 Bundler 1.7 is a security-only release to address CVE-2013-0334, a vulnerability where a gem might be installed from an unintended source server, p

                                      • テクノロジー
                                      • 2014/08/14 11:17
                                      • bundler
                                      • security
                                      • ruby
                                      • 2.2.0 Released - RubyGems Blog

                                        10 users

                                        blog.rubygems.org

                                        RubyGems 2.2.0 includes major enhancements, minor enhancements and bug fixes. To update to the latest RubyGems you can run: gem update --system If you need to upgrade or downgrade please follow the how to upgrade/downgrade RubyGems instructions. To install RubyGems by hand see the Download RubyGems page. Special thanks to Vít Ondruch and Michal Papis for testing and finding bugs in RubyGems as it

                                        • テクノロジー
                                        • 2013/12/27 11:30
                                        • ruby
                                        • 2.1.0 Released - RubyGems Blog

                                          10 users

                                          blog.rubygems.org

                                          RubyGems 2.1.0 includes several new features and a security update to fix CVE-2013-4287 To update to the latest RubyGems you can run: gem update --system If you need to upgrade or downgrade please follow the how to upgrade/downgrade RubyGems instructions. To install RubyGems by hand see the Download RubyGems page. Security fixes: RubyGems 2.0.7 and earlier are vulnerable to excessive CPU usage due

                                          • テクノロジー
                                          • 2013/09/10 09:39
                                          • gem
                                          • Ruby
                                          • Data Verification - RubyGems Blog

                                            3 users

                                            blog.rubygems.org

                                            TL;DR: We were able to verify that all gems served by rubygems.org are tamper-free. The Incident As most people are aware, on January 30th rubygems.org was hit with a rogue code execution vulnerability. Much has been written (and will be written) about why the bug existed and how we’re going to be dealing with making sure it never happens again. Data Verification Right now, I want to let everyone

                                            • テクノロジー
                                            • 2013/02/02 04:04
                                            • ruby
                                            • security

                                            このページはまだ
                                            ブックマークされていません

                                            このページを最初にブックマークしてみませんか?

                                            『RubyGems Blog - RubyGems Blog』の新着エントリーを見る

                                            キーボードショートカット一覧

                                            j次のブックマーク

                                            k前のブックマーク

                                            lあとで読む

                                            eコメント一覧を開く

                                            oページを開く

                                            はてなブックマーク

                                            • 総合
                                            • 一般
                                            • 世の中
                                            • 政治と経済
                                            • 暮らし
                                            • 学び
                                            • テクノロジー
                                            • エンタメ
                                            • アニメとゲーム
                                            • おもしろ
                                            • アプリ・拡張機能
                                            • 開発ブログ
                                            • ヘルプ
                                            • お問い合わせ
                                            • ガイドライン
                                            • 利用規約
                                            • プライバシーポリシー
                                            • 利用者情報の外部送信について
                                            • ガイドライン
                                            • 利用規約
                                            • プライバシーポリシー
                                            • 利用者情報の外部送信について

                                            公式Twitter

                                            • 公式アカウント
                                            • ホットエントリー

                                            はてなのサービス

                                            • はてなブログ
                                            • はてなブログPro
                                            • 人力検索はてな
                                            • はてなブログ タグ
                                            • はてなニュース
                                            • ソレドコ
                                            • App Storeからダウンロード
                                            • Google Playで手に入れよう
                                            Copyright © 2005-2026 Hatena. All Rights Reserved.
                                            設定を変更しましたx