It's not often we see a supply chain attack on RubyGems. But with summer vacations in full swing, perhaps we should have expected one. It was still a surprise when I opened the triage queue this morning and found a suspicious new package waiting.
A brand-new gem called git_credential_manager
had four versions published in rapid succession. At first glance, all it appeared to do was download some b...
