Fixing the Dependency Confusion Vulnerability in 600+ Ruby Apps (2022)
How Shopify solved the dependency confusion vulnerability in over 600 Ruby applications and created tailored large-scale migration tooling to make it easier.
blog | Infrastructure How We Fixed the Dependency Confusion Vulnerability in Over 600 Ruby Applications How Shopify solved the dependency confusion vulnerability in over 600 Ruby applications and created tailored large-scale migration tooling to make it easier. Published on Jan 27, 2022 Shopify has grown significantly over the years, and our success makes us an attractive target for malicious actors. We take the safety of our merchants seriously, so we have a good reason to continuously improve the security at Shopify. I’ll share how the Ruby Conventions team, which focuses on creating convent
saved by
related reading
- Programming language evolution: with all that, we are still flyingzverok.github.io
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Mediummedium.com
- Rewriting Bun in Rust | Bun Blogbun.com
- OpenAI agents carried out an undisclosed cyber-attack on RubyGemsrubyhack.ai
- State of DevSecOps | Datadogdatadoghq.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- OWASP Foundation - The Open Source Foundation for Application Securityowasp.org
- A Bunch of Programming Advice I'd Give To Myself 15 Years Ago | Marcus' Blogmbuffett.com
- Fixing Rust's supply chain security: The good, the bad and the uglykerkour.com
- Semantic Versioning 2.0.0 | Semantic Versioningsemver.org
- Semantic Versioning - Rust Project Primerrustprojectprimer.com
- Overriding Dependencies - The Cargo Bookdoc.rust-lang.org