A Practical Guide to Using Signed Ruby Gems - Part 1: Bundler
blog.meldium.com
blog.meldium.com
Basically ssh's known_hosts for packages.
But really now: why is everyone so intent on centralized CA-based signing, when you don't even know 99% of the time who made the thing in the first place, but only care that it's the same person who made the ones before it?
I don't know exactly what this rationale was behind this model - I plan to explore this further in subsequent posts. I'm a relative neophyte to code signing - part of the reason I'm writing these posts is to teach myself how things work.
http://www.rubygems-openpgp-ca.org/blog/gem-signing-x509-and...
I've been trying to get people to sign with OpenPGP because that can be done first and then you can put an authentication system into place after the fact. You can't do this with X.509, if/when a CA comes into play all gems would need to be resigned and republished.
It sounds like it might be slightly out of date though, as it refers to the author as having just landed the patch, which happened 8 years ago.
Will gem creation time significantly increase ? Will gem install time significantly increase ?