Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ruby library release — gem is currently a security placeholder #88

Open
reidab opened this issue Aug 27, 2024 · 1 comment
Open

Ruby library release — gem is currently a security placeholder #88

reidab opened this issue Aug 27, 2024 · 1 comment

Comments

@reidab
Copy link

reidab commented Aug 27, 2024

The Ruby version of this library makes reference to installing with gem install flexpolyline and is set up as a gem with that name.

However, the published version of this package at https://rubygems.org/gems/flexpolyline/ is an empty placeholder set up by @mensfeld of the RubyGems Security Team, presumably because this library was never actually published.

I believe someone from this project needs to contact RubyGems to regain control of the package and then cut a working release so that the library is accessible.

@mensfeld
Copy link

@reidab, yes, exactly. I did this because packages like this are frequent target to brandjacking. Happy to hand it to the team :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants