1. 5

Note: this is separate from https://lobste.rs/s/qij18r/sql_injection_vulnerability_in_all_versions_of_ruby_on_rails_activerecord_cve-2012-5664

  1.  

  2. 1

    http://rubygems.org was down for a bit this evening, presumably due to all the load from people upgrading their Rails sites. Why isn’t the bundler/gems stuff mirrored across multiple domains/servers/countries for redundancy? With everyone’s Gemfile pointing at rubygems.org by default, surely that site being down delayed some sites in upgrading as soon as they could have otherwise.