RubyGems/Bundler maintainer Hiroshi Shibata discusses whether to add a 'cooldown' feature — a waiting period before newly released packages can be installed — as a supply chain security measure. He surveys how other ecosystems (npm, pnpm, Bun, Deno, uv, pip) have already adopted cooldowns, then outlines the pros and cons:
Table of contents
TL;DRWhat Is a Cooldown?The LandscapeWhere Does Ruby Stand?What We're ConsideringConclusionNotesSort: