Protecting rubygems.org from the outside in: DoS prevention and compromised passwords
Every gem published to rubygems.org ends up running on someone’s computer. It’s up to rubygems.org to ensure that each gem contains what it claims, that its metadata is well-formed, and that the person who pushed it is who they say they are. We’ve been chipping away at that. Over the past few months, we shipped two changes that tighten rubygems.org ’s defences at very different layers: stronger validation of gem contents at push time, and integration with Have I Been Pwned to catch compromised passwords at
评论
?
参与讨论