Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Gem name validates_url vs validate_url #145

Open
swanson opened this issue Feb 15, 2023 · 3 comments
Open

Gem name validates_url vs validate_url #145

swanson opened this issue Feb 15, 2023 · 3 comments

Comments

@swanson
Copy link

swanson commented Feb 15, 2023

Hi, I accidentally installed the validates_url gem (an empty "placeholder") because the repo name doesn't match the gem name.

I looks like the validates_url gem is available to use: https://rubygems.org/gems/validates_url

This gem is empty. It protects against brandjacking. You are welcome. If you think it is yours to own, just contact me.

@mensfeld

Any thoughts on publishing to both gem names or renaming the repo? (I've been told that GitHub will handle redirects of repo renames very gracefully).

@kritik
Copy link
Member

kritik commented Feb 16, 2023

second name doesn't belong to this company

@swanson
Copy link
Author

swanson commented Feb 16, 2023

second name doesn't belong to this company

The user @mensfeld can transfer the validates_url gem name. They are holding the gem name to avoid something using it for malicious purposes if you accidentally use the wrong name.

@mensfeld
Copy link

@swanson @kritik you are welcome ;) that's a typosquatting attack prevention. It was used few times already to steal data from ppl that accidentally installed this.

If you (@kritik) want the name, just DM me and will be happy to transfer the ownership.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants