How a routine gem update ended up creating $73k worth of subscriptions
The Insider News
1
Posts
1
Posters
0
Views
1
Watching
-
On November 5, 2021 (a Friday of course), we've deployed innocent-looking gem updates. Minor versions of Ruby on Rails, Ruby Sentry client, Ruby Slack client, http libraries, Puma, Devise, OmniAuth Ruby client, Mongoid, and a few test gems. However, something went very wrong.
MongoDB - I knew it was them! Even when it was the bears, I knew it was them!