Skip to content

Bump oauth to 1.1.1 - #4764

Merged
CloCkWeRX merged 2 commits into
devfrom
bump-oauth-1.1.1
Aug 23, 2026
Merged

CloCkWeRX merged 2 commits into
devfrom
bump-oauth-1.1.1

Conversation

@CloCkWeRX

@CloCkWeRX CloCkWeRX commented Aug 23, 2026 •

Copy link
Copy Markdown
Collaborator

ruby-oauth/oauth@v1.1.0...v1.1.1

Showing 343 changed files with 36,715 additions and 4,595 deletions.

I did some manual review, docs added, a bunch of binaries (good lord, why).

ChatGPT boiled an ocean for:

Area Assessment
Obvious malware in require "oauth" path Not found
Hard-coded exfiltration endpoint Not found
Shell execution in normal runtime Not found
Credential harvesting in OAuth implementation Not found
Obfuscated Ruby Not found
Suspicious new network code Not found
OAuth escaping change Legitimate-looking
oauth-tty dependency floor Suspicious / deserves investigation
version_gem dependency floor Suspicious but currently benign-looking
Gem signing/private-key code High-interest build-time attack surface
Huge unrelated diff Supply-chain red flag, but not proof
Changelog claims Ignored

And the deps:

Dependency Supply-chain concern Code-level finding
oauth-tty 1.0.6 🔴 High interest Huge 237-file / 43-commit update after 3 years; new release infrastructure; no malicious runtime code found so far
version_gem 1.1.9 🟠 Moderate interest Huge 157-file / 48-commit update; runtime code essentially unchanged; gemspec/release machinery substantially changed
snaky_hash 🟢 No version floor change Not newly introduced by 1.1.1
base64 🟢 Standard library gem Not relevant to the suspicious update

@CloCkWeRX

Copy link
Copy Markdown
Collaborator Author

Note to self: if possible, we should drop this as it's impossible to audit

@CloCkWeRX
CloCkWeRX marked this pull request as ready for review August 23, 2026 08:04
@CloCkWeRX
CloCkWeRX merged commit f331361 into dev Aug 23, 2026
16 checks passed
@CloCkWeRX
CloCkWeRX deleted the bump-oauth-1.1.1 branch August 23, 2026 08:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant