Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Socket
Socket
@SocketSecurity@fosstodon.org  路  activity timestamp 5 days ago

馃拵 The Gem Cooperative is testing dependency cooldowns at the registry level, delaying access to newly published gems rather than relying on client tooling. An interesting infrastructure experiment to reduce exposure to malicious #Ruby gems during supply chain attacks:

https://socket.dev/blog/gem-coop-tests-dependency-cooldowns

Socket

gem.coop Tests Dependency Cooldowns as Package Ecosystems Mo...

gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct