Cooldown Support for Ruby Bundler

88 points - last Wednesday at 5:15 AM

Source

Comments

swader999 today at 2:54 PM
Aren't we back to the drawing board once everyone uses this?
doctorpangloss today at 3:40 PM
you have 1.0 installed. you enable 7 day cooldowns. an exploit is discovered in 1.0, and 1.1 is immediately released to fix the exploit. do you sit on 1.0 for 7 days?
delichon today at 2:21 PM
> A version whose source does not expose created_at, such as older gem servers, historical entries from before the v2 cutover, or private registries still on the v1 format, is treated as outside the window and stays resolvable.

How is that not an easy exploit to circumvent the cooldown?