logoalt Hacker News

Cooldown Support for Ruby Bundler

36 pointsby calyhrelast Wednesday at 5:15 AM7 commentsview on HN

Comments

swader999today at 2:54 PM

Aren't we back to the drawing board once everyone uses this?

show 5 replies
delichontoday at 2:21 PM

> A version whose source does not expose created_at, such as older gem servers, historical entries from before the v2 cutover, or private registries still on the v1 format, is treated as outside the window and stays resolvable.

How is that not an easy exploit to circumvent the cooldown?

show 2 replies