logo

RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems

ID: a54a4693-4f8b-5604-83d7-cfaa71077138

STIX ID: report--a54a4693-4f8b-5604-83d7-cfaa71077138

Feed Name: Socket Blog

Date Published: 2026-06-05

Date Updated: 2026-06-11

Author: Sarah Gooding

...
...

RubyGems and Bundler 4.0.13 add an opt-in "cooldown" that prevents dependency resolution from selecting gem versions published within a configurable recent time window, using per-version created_at timestamps from the compact index. The report covers how cooldown is applied, configuration options (per-source, project, global, environment, and CLI), behavior when timestamps are unavailable, visibility in bundle outdated, and the security trade-offs between delaying possible malicious releases and delaying urgent fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.