Ruby Weekly issue #810 covers a RubyGems security incident where a CDN caching bug exposed legacy API keys to other users, prompting a mass revocation. Truffle Security researcher Luke Marshall published a full technical writeup of the exploit. Other highlights include a guide to ActiveModel conditional validations, a proposal to deprecate ruby2_keywords, a CRuby escape analysis optimization proposal, and a preview of Ruby 4.1 additions to String#unpack/unpack1 including new LEB128 and alignment directives.
2 Impressions