Giter Site home page Giter Site logo

rubyinstaller.org-website's People

Contributors

ashmaroli avatar ccmywish avatar dependabot[bot] avatar edsf avatar gmile avatar kjarrigan avatar larskanis avatar luislavena avatar markdblackwell avatar olleolleolle avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

rubyinstaller.org-website's Issues

GPG Verify rubyinstaller-devkit-3.0.2-1-x64.exe

Hi,

I did below mentioned steps to verify rubyinstaller-devkit-3.0.2-1-x64.exe file.
OS: Windows 10

Import signing key

gpg --import ci.ri2-package-signing-key.asc
gpg: key 30B77F3A: "ci.ri2 package signing key" not changed
gpg: Total number processed: 1
gpg: unchanged: 1

Verify Downloaded File

gpg --verify rubyinstaller-devkit-3.0.2-1-x64.exe.asc
gpg: assuming signed data in 'rubyinstaller-devkit-3.0.2-1-x64.exe'
gpg: Signature made 07/10/21 01:46:32 Standard Time using RSA key ID AAE32BA7
gpg: Can't check signature: No public key

I downloaded signing key from https://rubyinstaller.org/ci.ri2-package-signing-key.asc.
So far I was not able to verify the download.
Is the signing key updated for new versions of Rubyinstaller?

Thank You,
Chamal.

Recommend a version to use?

Noticed that the home page doesn't really recommend a version to install.

Assuming that:

  1. Most extension gems are now testing with 2.5 (and many with trunk).
  2. For the first time, most of 2.5 was in development with full testing (test-all & test-spec) on 64 bit builds. Not the case with 2.4.

Might it be helpful for users to know that the recommendation is to use 2.5.x-x64 unless one has a particular need? I'm not that familiar with the layout or Jekyll, but I'd be happy to try...

Greg

rubyinstaller2.org is redirecting to rubyinstaller.org

FYI, bought rubyinstaller2.org domain and setup to permanently redirect to existing domain. That is done as page rules in Cloudflare.

Thought was worth mentioning in case seeing some weird referrals in the analytics.

Cheers.

PS: @larskanis, thank you for your hard work maintaining RubyInstaller2 ❤️ ❤️ ❤️

Compromised subdomain

Hello, I am a contributor to the Ruffle project, and while remediating a compromise of an unused subdomain of our website, we found that your project's website had been compromised by the same threat actor. Below I will explain the details of the issue and how you can resolve it.

A subdomain of your project website has been compromised and is displaying a spam advertisement for an Indonesian gambling service. The compromised URL is "direct.rubyinstaller.org". The attack was possible because these three conditions were met:

  1. You have a DNS entry for the domain "direct.rubyinstaller.org" pointing to GitHub Pages.
  2. You do not have a GitHub Pages repository with a CNAME file pointing to that domain.
  3. You do not have verification set up for GitHub Pages: https://docs.github.com/en/pages/configuring-a-custom-domain-for-your-github-pages-site/verifying-your-custom-domain-for-github-pages

Because your domain's DNS entry points to GitHub Pages, but you do not have verification set up, an attacker was able to claim your custom domain by simply creating a GitHub Pages repository and adding a CNAME file within it pointing to your domain. The GitHub Docs page I linked above explains it this way:

When you verify your custom domain for your personal account or organization, only repositories owned by your personal account or organization may be used to publish a GitHub Pages site to the verified custom domain or the domain's immediate subdomains.

Verifying your domain stops other GitHub users from taking over your custom domain and using it to publish their own GitHub Pages site. Domain takeovers can happen when you delete your repository, when your billing plan is downgraded, or after any other change which unlinks the custom domain or disables GitHub Pages while the domain remains configured for GitHub Pages and is not verified.

So there are two steps you should take immediately:

  1. Remove the DNS entries for any unused subdomains of your website pointing to GitHub Pages, including the DNS entry for "direct.rubyinstaller.org".
  2. Set up verification for GitHub Pages by following the instructions in the GitHub Docs page I linked above. Here is the link again: https://docs.github.com/en/pages/configuring-a-custom-domain-for-your-github-pages-site/verifying-your-custom-domain-for-github-pages

Once again, I found this issue with your site because we at the Ruffle project were facing the exact same compromise, and were able to take the steps above to resolve it. Let me know if I can be of any further assistance!

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.