All versions of RubyGems are vulnerable to Persistent Code Injection via
the gemspecs, which RubyGems generates when installing a Gem.</b>
== Explanation
When building a +.gem+ file, RubyGems will load your pure-Ruby gemspec
== Solution
The fix for this bug is rather simple, the +ruby_code+ method should
call <tt>String#dump</tt> or <tt>String#inspect</tt> instead of naively
wrapping the Strings in <tt>%q{ }</tt>.

