sbp commented on issue #718:
URL: 
https://github.com/apache/tooling-trusted-releases/issues/718#issuecomment-3991617362

   The exhaustion attack is against the whole server, so if a temporary 
directory is filled up then it's too late. I think the reason why we said that 
we should lint ignore this is because we would probably notice an attack 
against `svn:dist` before ATR. But we don't even know yet how much disk space 
the production instance of ATR will be allocated. What if it's a small fraction 
of the disk space on the `svn:dist` server(s)? What if it's a small fraction 
_after_ all the other things that ATR needs to do?


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to