134 points by calyhre 3 days ago | 31 comments | View on ycombinator
ashishb about 4 hours ago |
swader999 about 7 hours ago |
tancop about 4 hours ago |
delichon about 8 hours ago |
How is that not an easy exploit to circumvent the cooldown?
doctorpangloss about 6 hours ago |
shevy-java about 4 hours ago |
How active is rubygems.org itself? I retired when the 100k download threshold was installed onto developers there; on github I don't have any such restriction pertaining to code I publish and maintain. But even before that restriction, numerous gems were abandoned. I understand that this is a natural cycle anyway, but without an influx of new developers, ruby will fossilize and age out just as perl did before.
None of those "cooldowns" will bring in new developers either. It all seems to be about meta-appeasing companies; this could indirectly help, but I doubt it will help much.
So, just like COVID-19 used air travel, modern malware attacks are relying on GitHub+dependabot to speed up the spread.
Even for single page website built using Vue, I would get about 5 updates a week.