Skip to content

Conversation

@andrew
Copy link

@andrew andrew commented Dec 17, 2025

I used https://packages.ecosyste.ms to get the list of the top ruby gem names for typosquatting detection.

The rubygems.org api doesn't expose email addresses so can't use some of the Email-based detectors.

Gem extraction handles the nested tar format (.gem contains data.tar.gz)

Added tests for the ruby semgrep rules

@andrew andrew force-pushed the main branch 2 times, most recently from e9a7cc4 to 2e5e5a7 Compare December 17, 2025 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant