frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Cooldown Support for Ruby Bundler

https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html
37•calyhre•2d ago

Comments

delichon•51m ago
> A version whose source does not expose created_at, such as older gem servers, historical entries from before the v2 cutover, or private registries still on the v1 format, is treated as outside the window and stays resolvable.

How is that not an easy exploit to circumvent the cooldown?

OptionOfT•31m ago
Can you in your own gem depend on gems from another server? Or does it need to be configured on the client?

If not, and the current defacto standard gem server doesn't accept v1 anymore, we're good I suppose?

werdnapk•4m ago
Most gems in Ruby/Rails projects come from rubygems, so if they were published long ago, any exploits should have already been found hopefully. Any old gems that would attempt to release a new compromised version would now get a created_at timestamp and the cooldown applies.

Unless you can compromise the gem server to overwrite created_at fields, I don't see any exploits here.

Private gem servers are either already trusted (if they're your own) or already under some scrutiny and extra care already being taken (ideally), but this last case applies to very few projects I'm sure.

swader999•19m ago
Aren't we back to the drawing board once everyone uses this?
ihumanable•16m ago
Yea, all the new advice around using dependency cooldowns only works if _someone_ is installing these things before you and finding the vulnerabilities.

It seems like the advice right now is to become a freerider while there are still people installing closer to release that will do free work for you finding out there's something nasty in the release.

Once everyone is waiting 2 weeks to install an update, then the value of everyone waiting goes down dramatically.

kbenson•8m ago
This is how a chunk of people function anyway. There are plenty of people that choose to not install "point zero" release for software of a certain importance, assuming with any major changes there are often bugs that come along with it.

In this case, since the number of cool down days is configurable, even if everyone was using it we would still likely see a somewhat smooth curve for adoption, since not everyone will choose the same delay and the delay time will likely map closely to how people want to habdke risk.

It's all a trade off, just like it's always been. This just makes it simpler to act on what you want your risk/comfort level to be.

password4321•15m ago
The point is to allow the automated scanners a chance to run.

Every security company and their cousin wants to be the one to find the next big dependency malware.

grncdr•14m ago
I think the idea is that dedicated security firms and/or automated scanners will discover exploits in the cooldown period.
teeray•3m ago
[delayed]

Astronauts on ISS told to shelter as repairs under way to fix air leaks

https://www.bbc.com/news/live/c4g44ew3g1kt
29•janpot•12m ago•3 comments

Mouseless – keyboard-driven control of macOS/Linux/Windows

https://mouseless.click
176•riddley•2d ago•89 comments

Cooldown Support for Ruby Bundler

https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html
38•calyhre•2d ago•8 comments

Tracing a powerful GNSS interference source over Europe

https://arxiv.org/abs/2606.03673
239•mimorigasaka•6h ago•106 comments

Redis 8.8: New array data structure, rate limiter, performance improvements

https://redis.io/blog/announcing-redis-8-8/
107•ksec•2d ago•53 comments

India's surprise baby bust is a warning to the world

https://www.economist.com/leaders/2026/06/04/indias-surprise-baby-bust-is-a-warning-to-the-world
8•hakonbogen•28m ago•7 comments

Changing how we develop Ladybird

https://ladybird.org/posts/changing-how-we-develop-ladybird/
606•EdwinHoksberg•7h ago•396 comments

C++: The Documentary

https://herbsutter.com/2026/06/04/c-the-documentary-released-today/
261•ingve•10h ago•178 comments

Entanglement Builds Space-Time. Now "Magic" Gives It Gravity

https://www.quantamagazine.org/entanglement-builds-space-time-now-magic-gives-it-gravity-20260603/
103•rbanffy•6h ago•82 comments

databow: a Rust CLI to query any database with an ADBC driver

https://columnar.tech/blog/introducing-databow//
91•hckshr•2d ago•19 comments

ESP32 Bit Pirate, a Hardware Hacking Tool with WebCLI That Speaks Every Protocol

https://github.com/geo-tp/ESP32-Bit-Pirate
94•geotp•7h ago•33 comments

Nango (YC W23, dev infra) is hiring staff back end engineers

https://nango.dev/careers
1•bastienbeurier•3h ago

Fine-tuning an LLM to write docs like it's 1995

https://passo.uno/fine-tuning-docs-llm/
136•taubek•9h ago•49 comments

Meta enables ADB on deprecated Portal devices [video]

https://fb.watch/HxPu0fSyeH/
268•jenders•14h ago•107 comments

Lee Kuan Yew's Singapore Story (2023)

https://www.historytoday.com/archive/feature/lee-kuan-yews-singapore-story
89•pepys•7h ago•77 comments

Azure Linux 4.0 is Microsoft's first general-purpose Linux

https://www.boxofcables.dev/azure-linux-4-0-is-microsofts-first-general-purpose-linux/
137•haydenbarnes•11h ago•114 comments

Leap in DNA synthesis slashes time to build new genetic sequences

https://spectrum.ieee.org/faster-dna-synthesis-sidewinder
82•natalcleft•21h ago•18 comments

At the Autograph Show

https://oldster.substack.com/p/at-the-autograph-show
25•NaOH•2d ago•2 comments

Anthropic's open-source framework for AI-powered vulnerability discovery

https://github.com/anthropics/defending-code-reference-harness
480•binyu•19h ago•135 comments

New York just passed a one-year temporary ban on data centers

https://scienceaim.com/new-york-just-passed-a-one-year-temporary-ban-on-data-centers/
11•binarymax•23m ago•6 comments

The IsUpMap lets you check the status of over 100 major sites at once

https://isupmap.com/
101•mikelgan•10h ago•36 comments

I'm skeptical about efforts to revolutionize schooling

https://www.scotthyoung.com/blog/2026/05/27/revolutionize-schooling/
252•andrewstuart•2d ago•392 comments

Show HN: Lowfat – pluggable CLI filter that saved 91.8% of my LLM tokens

https://github.com/zdk/lowfat
44•zdkaster•6h ago•31 comments

Open Code Review – An AI-powered code review CLI tool

https://github.com/alibaba/open-code-review
230•geoffbp•15h ago•66 comments

Do transformers need three projections? Systematic study of QKV variants

https://arxiv.org/abs/2606.04032
193•Anon84•16h ago•36 comments

Show HN: I benchmarked LLM agents on fixing real-world security vulnerabilities

https://giovannigatti.github.io/cve-bench/
4•ggattip•7h ago•1 comments

Communication on European Tech Sovereignty, and an EU Open-Source Strategy

https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompan...
76•jrepinc•4h ago•46 comments

Programmers will document for Claude, but not for each other

https://blog.plover.com/2026/03/09/#documentation-wins-2
85•surprisetalk•2h ago•89 comments

Watching a Z80 from an RP2350

https://emalliab.wordpress.com/2026/05/26/watching-a-z80-from-an-rp2350/
40•ibobev•2d ago•7 comments

Meta's ships facial recognition on smart glasses

https://www.buchodi.com/meta-glasses-facial-recognition/
290•buchodi•19h ago•258 comments