Both approaches allows code injection, such as:

```
%gemspec_add_runtime_dependency -n fog-dynect ['~> 10.0', '>= 10.1.1'];
puts requirements
```

But I don't consider this harmful ....


Vít
_______________________________________________
ruby-sig mailing list
ruby-sig@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/ruby-sig@lists.fedoraproject.org

Reply via email to