Fixing the Dependency Confusion Vulnerability in 600+ Ruby Apps (2022)
How Shopify solved the dependency confusion vulnerability in over 600 Ruby applications and created tailored large-scale migration tooling to make it easier.
blog | Infrastructure How We Fixed the Dependency Confusion Vulnerability in Over 600 Ruby Applications How Shopify solved the dependency confusion vulnerability in over 600 Ruby applications and created tailored large-scale migration tooling to make it easier. Published on Jan 27, 2022 Shopify has grown significantly over the years, and our success makes us an attractive target for malicious actors. We take the safety of our merchants seriously, so we have a good reason to continuously improve the security at Shopify. I’ll share how the Ruby Conventions team, which focuses on creating convent
Explore this link on the map →saved by
related reading
- Programming language evolution: with all that, we are still flyingzverok.github.io
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Mediummedium.com
- Rewriting Bun in Rust | Bun Blogbun.com
- State of DevSecOps | Datadogdatadoghq.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- A Bunch of Programming Advice I'd Give To Myself 15 Years Ago | Marcus' Blogmbuffett.com
- Semantic Versioning 2.0.0 | Semantic Versioningsemver.org
- Overriding Dependencies - The Cargo Bookdoc.rust-lang.org
- Security incident disclosure — July 2026huggingface.co
- NPM Install Everything, and the Complete and Utter Chaos That Followsboehs.org
- We should all be using dependency cooldownsblog.yossarian.net
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io