Logo

Gemfury Blog

  • Random
  • Archive
  • RSS

Version Badge for NPM Modules

Since the original announcement two months ago, hundreds of package owners have installed the Version Badge, helping thousands of developers every day to quickly identify and find the installable package associated with a Github repo or a project webpage. Among many others, some notable projects are Devise, CanCan, Celluloid, and Slim.

Today, we are happy to introduce Version Badge for NPM modules.

Read More

  • 1 month ago
  • Permalink
  • Share
    Tweet

Unleash the Fury.io

Over the course of the last few months, we have been carefully extending Gemfury for multi-user and multi-language use. Today, we would like to announce two big changes to the way you download and install your packages.

Read More

  • 2 months ago
  • Permalink
  • Share
    Tweet

RubyGems.org Vulnerability Explained

After evaluating Gemfury’s processing of RubyGems, we feel it is important to share our understanding and bring awareness to possible security issues when parsing untrusted YAML input.

On January 30, 2013, the community package server RubyGems.org was compromised with a rogue code execution vulnerability. The all-volunteer team sprung to action and in the following 53 hours yanked the expoit, patched the vulnerability, verified all the existing gems, and migrated the service to AWS. As of today, the service has been restored and deemed safe for use.

Important: This vulnerability came from misuse of a standard YAML library and might not be specific to just RubyGems.org. Many applications depend on this library and are potentially vulnerable to a similar exploit if exposed to untrusted YAML input — please take this opportunity to audit and secure your own applications.

Read More

    • #ruby
    • #rubygems
    • #vulnerability
    • #yaml
    • #gempocalypse
  • 3 months ago
  • Permalink
  • Share
    Tweet

Gemfury Dev Center →

If you enjoy using Gemfury, you already know the benefits of DRY, encapsulation, and modularizing your code. However, building a new Gem is still not as easy as sticking a stray file or two into ./lib.

Today, we’re opening the Gemfury Dev Center as the best place to learn about packaging code. As we read countless blog posts, emails, and raw code, we will continue to extract some of the most precious tips, tricks, and other gems (haha, get it?) to share with you.

Read More

  • 9 months ago
  • Permalink
  • Share
    Tweet

HTTPS: Is your URL string secure over SSL?

This article has been moved to the Gemfury Dev Center

Source: devcenter.gemfury.com

    • #https
    • #networking
    • #osi model
    • #security
    • #ssl
    • #tls
  • 1 year ago
  • Permalink
  • Share
    Tweet

Introducing Gemfury for Ruby

Today we’re officially launching Gemfury to finally bring all the conveniences of RubyGems to your private Gems. What started as an internal collection of scripts has finally turned into a “real thing.” We love using it, and hope that you will too.

Gemfury Screenshot

Read More

    • #bundler
    • #heroku
    • #rails
    • #ruby
    • #rubygems
    • #rubyonrails
  • 1 year ago
  • Permalink
  • Share
    Tweet

About

Gemfury is a cloud hosting for your private and custom packages. Once uploaded, you can install private RubyGems, Python packages, or Node.js modules into your app. It's simple, reliable, and hassle-free.

Try Gemfury

  • Create an account
  • See Plans & Pricing
  • How it Works

Follow Gemfury

  • @gemfury on Twitter
  • Facebook Profile
  • gemfury on github
  • RSS
  • Random
  • Archive
  • Mobile

Effector Theme by Carlo Franco.

Powered by Tumblr