From: Tom Copeland Date: 2007-01-17T23:44:31+09:00 Subject: Re: Hoe poisoned in Rubyforge On Sun, 2007-01-14 at 13:50 -0500, Tom Copeland wrote: > On Sun, 2007-01-14 at 13:20 -0500, Tom Copeland wrote: > > On Mon, 2007-01-15 at 00:56 +0900, SonOfLilit wrote: > > > So if I have a RubyForge account I can upload a modified gem, of, say, > > > Rails, with a backdoor, and unknowing ruby users will accidentally install > > > it and open a backdoor in production rails servers? > > > > We built various checks into the gem index builder on RubyForge > > to prevent overlapping gems from being deployed. Perhaps there are > > holes in these checks, and if so, we'll fix them. > > Also, it seemed prudent to not deploy any more gems until we get this > sorted out. So I've commented out the cron job that does that. There's a fix in place for this now and gems are being deployed as usual. There were several gems whose spec.full_name settings prevented them from being deployed; I'll contact those folks offline. Generally, if you have a project called "foo", you'll need to name the gem something like "foo-4.2.gem" for it to be deployed on the RubyForge gem index. Of course, you can release a file with whatever name you want on your project; this naming limitation only applies if you want the gem indexed. Questions and comments are welcome, Yours, Tom