Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove test files from gem #405

Merged
merged 1 commit into from Sep 25, 2019
Merged

Remove test files from gem #405

merged 1 commit into from Sep 25, 2019

Conversation

jdleesmiller
Copy link
Member

Remove the test_files from the gemspec, because rubyzip's test files are quite large now and include some malicious zip files that trigger virus scanners on machines that have the gem installed.

Fix #384 .

The trend in rubygems/rubygems#735 seems to be to remove test_files files from the gemspec. There is some good discussion in that ticket about why this may not be the best thing to do long term (pending changes in rubygems to better support test files), but it does seem to be the preferred approach at the moment.

I am planning to add this to the upcoming 2.0 release. I will leave this open for approximately one week for comment.

CC @MaximeDerche @GElkayam

@hainesr
Copy link
Member

hainesr commented Sep 21, 2019

I think this is a sensible change.

@jdleesmiller jdleesmiller merged commit 3641a96 into master Sep 25, 2019
@jdleesmiller jdleesmiller deleted the remove-test-files branch September 25, 2019 19:40
This was referenced Mar 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Tests for the Zip Slip vuln raise alarms by ClamAV antivirus...
2 participants