Skip to content

leap_cli: provide signed gems

There are various transport security issues with gems, providing a signed gem would mitigate many of these issues. Here is a step-by-step guide: https://www.trustwave.com/Resources/SpiderLabs-Blog/Signed-Ruby-Gems--A-c7decrypt-walk-through/

For more information about the ruby gem security issues have a look at: https://www.trustwave.com/Resources/SpiderLabs-Blog/Attacking-Ruby-Gem-Security-with-CVE-2015-3900/

(from redmine: created on 2015-06-23)