3 ms·
Glad to see the ruby community handled this quickly and professionally. Proud rubyist here. Far cry from the way a recent npm vuln was handled.
by igolden 7y ago
Glad to see the ruby community handled this quickly and professionally. Proud rubyist here.
Far cry from the way a recent npm vuln was handled.
- jake-low 7y agoAre you referencing the ESLint backdoor? From my recollection, the two incidents seem really similar. Both were noticed and unpublished quickly. Both could have been prevented by 2FA. Can you elaborate on why you think this incident was handled better?
- gedy 7y agoFor some reason, a subset of Rails community feels compelled to boost it by knocking whatever is more popular, e.g. Java in the old days, JavaScript these days. Rails is fine, but that aspect of the community is unnecessary and immature.
- uponcoffee 7y agoIt's not fair characterize a whole community by the actions of individuals; it's just throwing around more mud. Aside from the root comment, there is no evidence here to support the broad strokes you're making.
- gedy 7y agoI specified subset, and it's from my experiences over the years.
- zer01 7y agoYeah if you're going to sling shit like this, link to your sources. I've handled incidents involving both ecosystems over the past year and they're pretty comparable. NPM also bought a security company (https://blog.npmjs.org/post/172793182214/npm-acquires-lift-security-and-node-security https://blog.npmjs.org/post/172793182214/npm-acquires-lift-s...) and integrated NSP directly into NPM in the form of `npm audit`. Ruby/Gems has `bundler-audit`, which is equally good, but a separate project with a looser integration.
- igolden 7y agoTo all replies of this comment - it came off wrong. I didn't mean to "sling shit". I was referring to the 'event-stream' incident in which the package maintainer unknowingly passed it off to a new malicious maintainer (he has 100s modules). The farcry between the two was that the original maintainer basically wiped his hands clean from incident, whereas in this _specific_ scenario the maintainers of 'bootstrap-sass' offered suggestions on how to improve the security and prevent similar events in the future. I was impressed by the prompt and professional response by the maintainers, that's all. That being said - I generalized my comment too much, and I agree with zer01 that npm and bundler communities are very comparable and both do a great job.