Cool down before you install: give new gems a few days to be vetted - RubyGems Blog
04-Jun-2026 17
Most supply-chain attacks against RubyGems exploit a narrow window: an account is compromised, a malicious version ships, and any bundle install in the minutes that follow resolves straight to it. Bundler 4.0.13 introduces cooldown, a time-based filter that refuses to resolve to a version until it has been public for at least N days. Releases too new to have been scrutinized are passed over in favor of ones that have aged past the window.
.
Cool down before you install: give new gems a few days to be vetted - RubyGems Blog #ruby #rubydeveloper #rubyonrails #before #install: #vetted #RubyGems #blog #gems https://www.rubyonrails.ba/link/cool-down-before-you-install-give-new-gems-a-few-days-to-be-vetted-rubygems-blog-1