On Apr 1, 2009, at 07:25, aslak hellesoy wrote: > Most other packaging systems use MD5 signatures by default (apt-get, > pear, maven etc) > Why isn't Rubygems doing it? RubyGems provides it via signatures, if you want your package verifiable, add a signature.