> An audit of gem changes for the last 18 months did not find any examples of this vulnerability being used in a malicious way. A deeper audit for any possible use of this exploit is ongoing, and we will update this advisory once it is complete.
How would folks do that with strong enough guarantees? Surely they can't review every gem change by hand?