RubyGems/Bundler maintainer Hiroshi Shibata discusses whether to add a 'cooldown' feature — a waiting period before newly released packages can be installed — as a supply chain security measure. He surveys how other ecosystems (npm, pnpm, Bun, Deno, uv, pip) have already adopted cooldowns, then outlines the pros and cons:

5m read timeFrom dev.to
Post cover image
Table of contents
TL;DRWhat Is a Cooldown?The LandscapeWhere Does Ruby Stand?What We're ConsideringConclusionNotes

Sort: