logoalt Hacker News

insanitybityesterday at 4:33 PM1 replyview on HN

Arguably crates.io is worse. NPM has cooldowns and has for a while, it has had Trusted Publishing for longer, it has human-approved releases that separate CI/CD from actual publishing. Ruby is probably worse in every way.


Replies

woodruffwyesterday at 5:43 PM

RubyGems actually adopted Trusted Publishing before both npm and crates.io. To my recollection, they were second after PyPI.

(I have no opinion about the overall security posture of these indices.)

show 1 reply