RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems
ID: a54a4693-4f8b-5604-83d7-cfaa71077138
STIX ID: report--a54a4693-4f8b-5604-83d7-cfaa71077138
Feed Name: Socket Blog
RubyGems and Bundler 4.0.13 add an opt-in "cooldown" that prevents dependency resolution from selecting gem versions published within a configurable recent time window, using per-version created_at timestamps from the compact index. The report covers how cooldown is applied, configuration options (per-source, project, global, environment, and CLI), behavior when timestamps are unavailable, visibility in bundle outdated, and the security trade-offs between delaying possible malicious releases and delaying urgent fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
