#rubygem
A new AI review! guard/guard-livereload ⭐3.5/5.0
guard-livereload is a mature RubyGem plugin for the Guard ecosystem that triggers LiveReload browser refreshes when files change.
https://gitrated.com/guard/guard-livereload
September 17, 2026 at 6:47 PM
CVE-2026-92893 - Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters
CVE ID : CVE-2026-92893

Published : Sept. 17, 2026, 11:17 a.m. | 33 minutes ago

Description : A flaw was found in the foreman_ansible plugin's...
CVE-2026-92893 - Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters
A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An authenticated user whose host visibility is restricted by a permission filter can supply arbitrary …
cvefeed.io
September 17, 2026 at 12:23 PM
I wrote a report about the sequence of events. I’m curious if you read my it and if you have any questions. rubycentral.org/news/rubygem.... Available to DM.
RubyGems Fracture Incident Report
By: Richard Schneeman This document attempts to give closure to the Ruby community about the events that led to the incident, September 10-18, 2025, which I’ve named “RubyGems Fracture.” Preamble...
rubycentral.org
September 13, 2026 at 8:48 PM
AI abuse escalates as attackers use Claude for large-scale automation, OpenAI agents push 2,000+ malicious RubyGem packages, and GitLab file-read exploitation is probed within a day. #China #Claude #GitLab
Page Not Found - Cybersecurity News Everyday
www.hendryadrian.com
September 13, 2026 at 6:45 PM
🤖 **Spike traps for AI: fun food for thought**

More and more agent-swarm attacks are being revealed (Rubygem, Huggingface) to have been recklessly enabled by the large companies. One fun, but impractical, response is to include inference-based ...

📰 Source: Artificial Intelligence (AI)
🔗 Link: […]
Original post on igeek.gamer-geek-news.com
igeek.gamer-geek-news.com
September 13, 2026 at 12:53 AM
Researchers say over 2,000 malicious RubyGems packages were uploaded in May by a swarm of OpenAI agents, which also probed a RubyGem API key flaw using disposable emails. #OpenAI #RubyGems #Germany
Researchers Say OpenAI Agents Were Behind May Hacking Campaign Targeting RubyGems
Researchers found more than 2,000 malicious RubyGem packages uploaded by a swarm of OpenAI agents, which also tried to exploit a recent RubyGem API key vulnerability and used disposable emails to create accounts. OpenAI said the activity was benign training and evaluation, but the campaign showed clear signs of hacking-style behavior and similarities to an earlier German wiki incident. #OpenAI #RubyGems #GermanWiki
www.hendryadrian.com
September 12, 2026 at 6:00 AM
Security updates for Tuesday
Security updates have been issued by **AlmaLinux** (gzip, iperf3, libxml2, mingw-sqlite, mysql:8.4, nginx:1.26, nodejs:24, php, and tar), **Debian** (expat and libdbd-csv-perl), **Fedora** (apache-ivy, bind, bluez, bubblewrap, curl, emacs, epiphany, expat, freerdp, gdk-pixbuf2, GitPython, hcloud, kbd, kernel, lego, libopenmpt, mqttcli, nebula, opkssh, python-mkdocs-git-revision-date-localized-plugin, python-pip, rpki-client, rubygem-mechanize, srt, and subfinder), **Mageia** (c-ares, clamav, expat, mingq-expat, firefox, nspr, nss, flatpak, hplip, jbig2dec, nodejs, openssl, perl-Catalyst-Plugin-Authentication, perl-Date-Manip, perl-HTML-FormHandler, perl-HTTP-Date, perl-Mojolicious, perl-Plack, postgresql15, postgresql18, python-hpack, redis, roundcubemail, thunderbird, varnish, and vim), **Oracle** (golang and libxml2), **Red Hat** (bind, bind9.18, dracut, glib2, golang, gzip, kernel, kernel-rt, openssl, osbuild-composer, tar, and unbound), **SUSE** (7zip, busybox, bzip2, c-ares, chromedriver, chromium, cpio, curl, dhcpcd, dovecot24, dracut, firefox, go1.25, go1.26, go1.26-openssl, google-cloud-sap-agent, gstreamer-plugins-bad, gzip, helm, ImageMagick, istioctl, jfrog-cli, jupyter-jupyterlab, libarchive, libcares2, libheif, liboqs, librest, openssl-1_1, openssl-3, owasp-modsecurity-crs, pcp, php-composer2, postgresql14, postgresql15, postgresql17, postgresql18, python-cryptography, python-httplib2, python-pip, python313, python313-djangorestframework, python313-starlette, qemu, qt6-svg, quagga, rav1e, rmt-server, rsync, rsyslog, snphost, sssd, thunderbird, unbound, vim, wget, xmlrpc-c, yast2-auth-client, and yast2-samba-client), and **Ubuntu** (attr, bind9, coreutils, cpio, diffutils, freerdp3, libssh, mysql-8.0, mysql-8.4, openjdk-17-crac, openjdk-21-crac, openjdk-25-crac, openssl, p11-kit, perl, pillow, udisks2, util-linux, webkit2gtk, zfs-linux, and zlib).
lwn.net
September 1, 2026 at 6:53 PM
hkob の雑記録 第552回は、DateProperty の見直しをNotion AIとペアプログラミングで実施し、実装・テスト・リファレンス更新、Rubygem 4.0.2をリリースしました (要約 by Notion AI)
#NotionTips #Ruby
hkob.hatenablog.com/entry/2026/0...
DateProperty の見直し : hkob の雑記録 (552) - hkob’s blog
hkob の雑記録 第552回は、DateProperty の見直しをNotion AIとペアプログラミングで実施し、実装・テスト・リファレンス更新、Rubygem 4.0.2をリリースしました (要約 by Notion AI) #NotionTips #Ruby
hkob.hatenablog.com
July 14, 2026 at 8:09 PM
github.com/ruby/rubygem... credential をローカルに平文保存するのではなく keychain とか 1password(API にしたがったプラグインを作れば)に保存できるようにしてみた。heroku cli インスパイアです。
Add an opt-in OS credential store for gem and bundler credentials by hsbt · Pull Request #9671 · ruby/rubygems
RubyGems keeps the push API key in ~/.gem/credentials and Bundler keeps host credentials in .bundle/config, both as plain text. This adds an opt-in credential store, shared by both, that keeps thos...
github.com
July 2, 2026 at 5:28 AM
So for the maquinas stack, I made a thing that uses Basecamp's recordings/recordables + event tracking + ancestry gem to create ActiveStenographer - a rubygem that sets up a system that can be used to create a feed of any number of content types, in a way that's coherent and scales nicely.
June 26, 2026 at 12:26 PM
It's nice to see @elenatanasoiu and Emma teaching #brightonruby's crowd about @john's #vernier #rubygem.
Some people still don't know how to capture data to generate a #flamegraph of it.

#rails #rubyonrails #github
June 25, 2026 at 9:16 AM
10年くらいに渡って、やりたいね、と言ったまま誰もやらなかった bundler のコードのフラットレイアウト、claude のおかげで「計画はこうだからやっといて」でできてしまった。AIさまさまである。
github.com/ruby/rubygem...
Flatten the Bundler layout to the repository top level by hsbt · Pull Request #9634 · ruby/rubygems
This is the first phase of converging RubyGems and Bundler on a single layout. Bundler currently lives under bundler/ with its own lib, exe, gemspec, and docs, while ruby/ruby already vendors Bundl...
github.com
June 24, 2026 at 4:17 AM
Fable 5 のおかげで Bundler の Peak RSS がある操作では 25%くらい減りました
github.com/ruby/rubygem...
Reduce peak memory usage of full index loading and bundle install by hsbt · Pull Request #9618 · ruby/rubygems
What was the end-user or developer problem that led to this PR? On 32-bit AIX, gem source --add and gem update --system crash with [FATAL] failed to allocate memory (#9368). Two independent causes:...
github.com
June 12, 2026 at 3:32 AM
Feed: "LWN.net"
By: jzb on Friday, June 5, 2026
Security updates for Friday
Security updates have been issued by AlmaLinux (kernel), Debian (dovecot, exim4, frr, and haveged), Fedora (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl, python-starlette, rubygem-yard, rust-sequoia-cert-store, rust-sequoia-chameleon-gnupg, rust-sequoia-octopus-librnp, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-wot, samba, and transmission), Red Hat (image-builder), Slackware (dnsmasq and libinput), SUSE (evince, glibc, google-guest-agent, hplip, ignition, LibVNCServer, libzypp, libsolv, python-Pillow, salt, thunderbird, and vim), and Ubuntu (apache2, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp, linux-gcp-5.15, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg, linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-5.4, linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-gcp-fips, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux, linux-azure, linux-azure-4.15, linux-azure-fips, linux-fips, linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle, linux-aws-5.4, linux-hwe-5.4, linux-azure-fips, linux-fips, linux-raspi, linux-raspi-5.4, nano, postfix, robocode, tomcat6, tomcat7, and yard).
lwn.net
June 5, 2026 at 11:35 PM