houhoulis has quit [Ping timeout: 272 seconds]
houhoulis has joined #rubygems
houhoulis has quit [Ping timeout: 258 seconds]
houhoulis has joined #rubygems
houhoulis has quit [Ping timeout: 248 seconds]
houhoulis has joined #rubygems
houhoulis has quit [Remote host closed the connection]
_whitelogger has joined #rubygems
tubbo has joined #rubygems
<tubbo> hi folks...i'm having a bit of trouble understanding the idea behind signed gems.
<tubbo> reading a few different articles, it seems the solution is kinda haphazard and no one can agree on what we should be doing
<tubbo> mostly looking thru https://guides.rubygems.org/security/ and the rubygems-trust repo
<havenwood> tubbo: It's easy to check signatures with -P/--trust-policy but most gems aren't signed and most folk aren't checking signatures.
<havenwood> tubbo: I think the best path forward if we want to improve is to pick up the work on TUF: https://github.com/rubygems/rubygems/pull/719
tubbo has quit [Ping timeout: 268 seconds]
darix has quit [Quit: may the packets be with you...]
darix has joined #rubygems