Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable RubyGems MFA for Ruby repos #313

Open
nhtruong opened this issue Sep 14, 2023 · 1 comment
Open

Enable RubyGems MFA for Ruby repos #313

nhtruong opened this issue Sep 14, 2023 · 1 comment
Labels
enhancement New feature or request

Comments

@nhtruong
Copy link

nhtruong commented Sep 14, 2023

Is your feature request related to a problem? Please describe

If possible, we should enable MFA when interacting with Rubygems.org to improve security for our Ruby Gems.

I am aware that our one-click release pipeline automates most of the release process and adding an MFA might defeat the purpose of the pipeline (as someone from the build team will have to get involved in every Ruby Gem release). So, if we have already explored this avenue and determined that MFA is more troublesome than it's worth, please close this ticket.

Describe the solution you'd like

  • Update Release Workflow to use MFA when publish to Rubygems.org.
  • Update gemspec of our ruby gems to opt-in to MFA
@nhtruong nhtruong added enhancement New feature or request untriaged labels Sep 14, 2023
@gaiksaya
Copy link
Member

I believe MFA is enabled at the account level. Hence if we enable it wondering if we need to add the add the requirement in all gemspec files of all rubies under opensearch-project?
Also need to research a bit on MFA requirements when publishing a gem? Will it pop up MFA while publishing too?
Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: 📦 Backlog
Development

No branches or pull requests

2 participants