From: "Mauricio Fernández" Date: 2004-08-13T22:20:29+09:00 Subject: Re: RubyForge project and gem distriubtion On Fri, Aug 13, 2004 at 09:20:04PM +0900, Richard Kilmer wrote: > > anyone with a brain could get malicious code into > > any package available on the planet, be it debian > > or whatever. the fact that ruby is so dynamic only [...] > You don't need to run as root, only if you want to install in a system-wide > repository. Actually, RubyGems runs just great installed by a user, in > their own directories, with no r00t access at all. Its all a question of > what the target user/developer wants to do. > [...] > gem install --install-dir ~/mygems fxruby > > That's not too arduous ;) Please read http://ruby-talk.com/blade/109119. This is an issue you can solve easily. > > > > ignoring the problem and hoping people will just > > forgot it was ever brought up ain't gonna help. > > > > Alex > > I don't advocate ignoring it. I advocate in NOT giving a false sense of > security. Where's the false sense of security in "anyone with a brain could get malicious code into any package available on the planet" :-))) (sorry, I just find Alex' words too funny in this context :) -- Running Debian GNU/Linux Sid (unstable) batsman dot geo at yahoo dot com