4 ms·
Regarding #2, you could use gems from the github repositories (just specify the tag) instead of relying on gems hosted on RubyGems. Obviously then it is up to
by excid3 14y ago
Regarding #2, you could use gems from the github repositories (just specify the tag) instead of relying on gems hosted on RubyGems.
Obviously then it is up to you to verify everything, including that you're using the right versions and what not.
- purephase 14y agoProbably not safe enough as most of them probably list external dependencies that will fall back to rubygems.
- excid3 14y agoGood point.
- boonedocks 14y agoI'm not sure of the best way to go about it, but if all the dependency gems are also on Github, a script might be able to pull the SHAs from the right version of each dependency and return the proper entries for a Gemfile.
- purephase 14y agogemspecs/Gemfiles rarely list the gh repo, so you'll likely have to get it from a source which is probably rubygems. If it's compromised, they could update the gh repo location as well.
- boonedocks 14y agoI guess, at least for the most common gems, there could be an independent list which maps gem names to their Github repos. Of course, that list would have to be trustworthy. It would be nice to solve that mapping problem anyway, because sometimes it's not entirely clear which Github repo is the official source for a project.