Hacker News new | ask | show | jobs
by Ajedi32 2493 days ago
That's not really any better than 2FA against this specific threat.

But to answer your question, yes there is a system for signing gems, though it's not widely used: https://guides.rubygems.org/security/