Signing the gems you publish is underused, and here is the blind spot most miss: git-sourced gems in your Gemfile skip signature verification entirely, since only packaged .gem files can be verified. go.fastruby.io/sg9 #RubyGems
0 likes 0 replies
?
Signing the gems you publish is underused, and here is the blind spot most miss: git-sourced gems in your Gemfile skip signature verification entirely, since only packaged .gem files can be verified. go.fastruby.io/sg9 #RubyGems
0 likes 0 replies