RubyGems is not vulnerable to the xz/liblzma backdoor

Announcing Trusted Publishing on RubyGems.org

RubyGems now requires MFA for owners of top gems

Making popular Ruby packages more secure

RubyGems March 2019 Security Advisories

RubyGems.org 2016 Push

RubyGems.org gem replacement security vulnerability and mitigation

CVE-2015-3900 Request hijacking vulnerability in RubyGems 2.4.6 and earlier

Rewriting rubygems.org Git history