3 ms·
Importantly, every layer in the stack is responsible for it's own security. A consumer of this API should be making sure that it's optimally configured and conf
by donaldstufft 13y ago
Importantly, every layer in the stack is responsible for it's own security. A consumer of this API should be making sure that it's optimally configured and configure it differently where it's not. Any project that isn't doing that should have security reports sent to it to tell it to do that and if they refuse they are guilty of the same sort of negligence as ruby core.
However the fact that other people should also be claiming responsibility for their own security does not absolve ruby of it's own responsibilities.