Skip to content

build: require MFA for a manual push, and link the metadata - #20

Draft
simonx1 wants to merge 1 commit into
obie:mainfrom
simonx1:fix/gemspec-metadata
Draft

simonx1 wants to merge 1 commit into
obie:mainfrom
simonx1:fix/gemspec-metadata

Conversation

@simonx1

@simonx1 simonx1 commented Sep 18, 2026

Copy link
Copy Markdown

Releases go through trusted publishing, so no API key is stored anywhere and a push from CI needs no secret. That leaves the other door open: anyone holding a RubyGems credential for an owner of this gem can gem push from a laptop, and a leaked or reused token is enough. rubygems_mfa_required refuses that without a second factor. It costs nothing here, because the automated path doesn't use credentials at all.

Also adds bug_tracker_uri and documentation_uri, so the RubyGems page points at the issue tracker and the README rather than only at the repo root.

homepage_uri is deliberately not set: it would duplicate source_code_uri, and gem build --strict — which the release workflow runs — fails on that warning. Verified with rake release:build, which is that exact strict build.


Draft: part of a security and API-coverage audit, opened for reference rather than as a request for immediate review. Independent of the other branches, each off main. Suite green on Ruby 3.2.11, 3.3.8 and 3.4.8.

🤖 Generated with Claude Code

Releases go through trusted publishing, so no API key is stored anywhere
and a push from CI needs no secret. That leaves the other door open:
anyone holding a RubyGems credential for an owner of this gem can
`gem push` from a laptop, and a leaked or reused token is enough.
rubygems_mfa_required refuses that without a second factor. It costs
nothing here, because the automated path does not use credentials at all.

Also adds bug_tracker_uri and documentation_uri, so the RubyGems page
points at the issue tracker and the README rather than only at the repo
root. homepage_uri is deliberately not set: it would duplicate
source_code_uri, and `gem build --strict` -- which the release workflow
runs -- fails on that warning.

Verified with `rake release:build`, which is the strict build the release
workflow performs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant