General Tech
RubyGems Open Source Supply Chain Security and OpenAI
The RubyGems team has released a statement addressing concerns over supply chain security, specifically regarding OpenAI's involvement in the RubyGems package manager. The team has taken steps to mitigate potential risks, including auditing dependencies and removing vulnerable components. However, they have not yet removed OpenAI's dependencies from the RubyGems package manager. The team is working with the Ruby community to identify and address potential vulnerabilities. The issue arose due to OpenAI's acquisition of DALL-E, which included a dependency on a RubyGems package called 'ruby-openai', which was first introduced in 2021. The package has been removed, but the team is still auditing dependencies to ensure the integrity of the RubyGems supply chain.
Read the full article at rietta.com →