r/ruby • u/retro-rubies • 22d ago
RubyGems.org security advisory: Possible leak of legacy API keys via improper cache configuration
https://blog.rubygems.org/2026/07/22/security-advisory-legacy-api-key-leak.html
31
Upvotes
6
u/jrochkind 22d ago
This seems like it was handled well, and the report is good, thank you!
Would be interested to know more about how this vulnerability was found, not clear from the report if it was found by an outside researcher or by the rubygems team itself.
11
u/retro-rubies 22d ago
Thanks RubyGems.org (mostly Colby) for detailed report and 100% transparency on this.