Skip to content

Please Sign This Gem To Allow Verified Installations #816

@jfelchner

Description

@jfelchner

There are a lot of attacks that deal with spoofing dependencies and other supply chain attacks. Because thor is one of the most popular gems (and is a foundation for a lot of CLI-based apps), I think it makes sense to sign the gem releases so that users can be sure we're getting the genuine article.

By signing thor, any gem that depends on it can be installed with HighSecurity enabled.

This should be fairly trivial since thor has no runtime dependencies.

This is an older but still accurate step-by-step guide on how to do it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions