home.social

#bundler_audit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bundler_audit, aggregated by home.social.

fetched live
  1. Heads Up: it appears that one of this year's RubyGSoC proposed Ideas is to add an "official" `bundle audit` command to Bundler that would override/conflict with bundler-audit's own `bundle audit` command. This has the potential of confusing bundler-audit users, potentially breaking CIs, and creating backlash (aka drama).
    github.com/rubygsoc/rubygsoc/w

    I have submitted an issue raising concerns with this proposed RubyGSoC Idea.
    github.com/rubygsoc/rubygsoc/i

    #bundler_audit #rubygsoc #gsoc2026 #gsoc

  2. "Integrating the bundle-audit security tool into Bundler"
    Wow, this is news to me. No one from RubyCentral or the Bundler team has reached out to me about this recently? While I get the idea of vendoring popular tools/libraries, I still worry we're bloating up the base Ruby install again?
    rubycentral.org/news/stf-annou
    #bundler #bundler_audit #ruby