Images and publishing
Gem sources
Mirror rubygems.org or a private gem source for Bundler and gem install, with the same checks as the other types.
- Settings, Registries: switch on RubyGems source.
- Add a RubyGems registry. For rubygems.org use
https://rubygems.org. - Write gem rules: pattern
rackorrails-*, versions3.1.8,~> 3.1or>= 3.0, < 4. - Developers set a Bundler mirror. See Set up Bundler.
- Every gem has to match the sha256 its source lists for it. A gem with no listed checksum, or a different one, is refused and not kept.
- The version list a gem gets (
/info) holds only allowed versions, so Bundler resolves to an allowed one. - Bundler looks at the version list of every gem it might need, old versions included. A gem with nothing allowed shows no versions, so the resolver picks versions that do without it. Only a download of an unapproved gem opens a request.
- A refused download is answered with a 451 status, the one Bundler prints the reason for.
- Every gem is scanned for malware, checked against OSV, has its license read from rubygems.org, and waits out cooling off. Auto approve and Cache now work for gem rules too.
gem pushis not taken yet.