Forum: Ruby A guide to reporting security vulnerabilities in gems?

87cee4ccee0b5f4c442d039a9bd0b432?d=identicon&s=25 Joel Chippindale (Guest)
on 2014-07-01 09:47
(Received via mailing list)
A little while ago after a discussion on the London Ruby User Group
list [1] I tried and failed to find a concise guide to reporting
vulnerabilities in gems.

Recently, in an effort to plug this gap, I issued a pull request to the
Rubygems Guides [2] to address this.

Firstly, given that I feel that I know special knowledge in this area
have never reported a security vulnerability in a gem, I would really
appreciate your feedback on the proposed guide in the pull request.

Secondly in the guide I have suggested mailing this list with details of
the vulnerability. Do you think this is appropriate and if not where do
think would be a more appropriate place to post details of a


