#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
The Hidden Dangers in Your Gemfile: Supply Chain Attacks in RubyGems
201
·
fastruby.io
·
Nov. 12, 2025, 6:04 p.m.
Security
Supply chain attacks
rubygems
Software Security
Best Practices for Developers
Summary
This post discusses the recent supply chain attacks on RubyGems and provides advice on how developers can safeguard their projects from such threats, highlighting the importance of security in software development.
Read full post on fastruby.io →
MORE POSTS LIKE THIS
Cool down before you install: give new gems a few days to be vetted
Blog Rubygems ·
Jun 3, 2026
rubygems
bundler
Let's enable MFA for all Ruby gems
Thoughtbot ·
Apr 21, 2026
Security
rubygems
Security Baked Into the JVM: two Subjects, one call
nfrankel ·
Aug 9, 2026
Java
jvm
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
simonw ·
Jul 28, 2026
jinja
Python
CVE-2026-66066: Defending Against the “KindaRails2Shell” Pre-Auth RCE
Linode ·
Jul 30, 2026
CVE-2026-66066
KindaRails2Shell
github: Dependabot alerts on malicious packages across more ecosystems
Sujith Quintelier ·
Jul 29, 2026
Dependabot
OpenSSF
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google