Am I missing something here?
Am I missing something here?
No, enabling MFA for the most popular packages won't end all security, but also your strategy of targeting subdependencies isn't very good, every dependency of a popular project will be more popular than its dependent parent.
Lots and lots of gems depend on Rails and / or ActiveSupport. There's probably a lot more "glue" gems that are widely used for stuff like HTTP clients. Beyond that though, your typical gem doesn't have an enormous amount of dependencies, and there's a pretty good chance that the dependencies of the top X gems are themselves in the list of top X gems.
Sure, the maintainer could still naively update the dependencies and pull up a bad one during an update of the Popular Gem. But that Popular Gem update would have to happen after an attack on the dependency, and before the breach was discovered (assuming it has any way of being discovered before release of the popular package).