Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rubygems report "This gem version has been yanked" #593

Open
net1957 opened this issue Feb 5, 2023 · 5 comments
Open

rubygems report "This gem version has been yanked" #593

net1957 opened this issue Feb 5, 2023 · 5 comments

Comments

@net1957
Copy link

net1957 commented Feb 5, 2023

see https://my.diffend.io/gems/composite_primary_keys/14.0.5/14.0.6 or from https://rubygems.org/gems/composite_primary_keys/versions/14.0.6 and click on Review changes.

could you investigate about this issue. The git repository is at version 14.0.5

So i did install the 14.0.5 version, but I did that after I see the the version was going from 14.04 to 14.0.6. But not all users would do that.

Hope it's only a mistake with rubygems.

@cfis
Copy link
Contributor

cfis commented Feb 5, 2023

Ah - the 14.0.6 changes didn't get pushed to github (was on airplane when I did it). They are now pushed.

Both gems are fine, neither is yanked. 14.0.6 has a couple of bug fixes taken from the 13.0.* branch.

Not sure why RubyGems would say its yanked, not seeing that?

@net1957
Copy link
Author

net1957 commented Feb 5, 2023

At this time, GitHub seems OK, but rubygems is already on the yanked page
image

@cfis
Copy link
Contributor

cfis commented Feb 6, 2023

Weird - it is definitely not yanked. See rubygems.org:

https://rubygems.org/gems/composite_primary_keys/versions/14.0.6

Not sure why diffend.io thinks it is.

Anyway, going to close this ticket since I'm not seeing anything to do. Reopen if you'd like.

@net1957
Copy link
Author

net1957 commented Feb 6, 2023

perhaps resubmitting the gem to rubygems should trigger the rubygems vulnerability analysis and clear the mess?

@cfis
Copy link
Contributor

cfis commented Feb 6, 2023

Unfortunately, I don't think its possible to resubmit gems. You can only sumbit new gems (or yank old ones). Maybe contact diffend.io?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants