Ruby Central hired Trail of Bits to complete a security assessment and a competitive analysis of RubyGems.org, the official package management system for Ruby applications. Our competitive analysis focused on evaluating RubyGems by comparing it primarily against the Principles for Package Repository Security document with a small emphasis on comparing RubyGems against four other package managers (PyPI, npm, Go Packages, Cargo). Catch security issues during development with automated checks Continuously monitor for new vulnerabilities Test critical components that handle user input Build security testing into their development workflow Scale their security testing as the codebase and associated infrastructure grows