Skip to content

Cooldown announcement#265

Merged
hsbt merged 3 commits into
masterfrom
cooldown-announcement
Jun 3, 2026
Merged

Cooldown announcement#265
hsbt merged 3 commits into
masterfrom
cooldown-announcement

Conversation

@hsbt
Copy link
Copy Markdown
Member

@hsbt hsbt commented Jun 3, 2026

No description provided.

hsbt and others added 3 commits June 3, 2026 12:04
Announce the cooldown feature shipping in Bundler 4.0.13. Cooldown holds
back gem versions until they have been published for at least N days,
giving freshly-pushed releases time to be vetted before resolution picks
them up.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Link the cooldown announcement from the 4.0.13 release notes, and point
the cooldown post's upgrade step back at the release announcement.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Link the v2 compact index effort that exposes per-version created_at, and
thank the rubygems.org team whose server-side groundwork cooldown sits on.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 3, 2026 03:09
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new blog post announcing Bundler’s new “cooldown” resolution feature (to reduce supply-chain risk from very recent gem releases) and links to that post from the Bundler 4.0.13 release notes for discoverability.

Changes:

  • Add a new post explaining the cooldown feature, how it works, and how to enable/configure it.
  • Update the Bundler 4.0.13 release post to link to the new cooldown announcement post.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
_posts/2026-06-03-cooldown-let-new-gems-be-vetted.md New announcement post describing the cooldown feature and configuration options.
_posts/2026-06-03-4.0.13-released.md Adds a “See also” link from the security note to the new cooldown announcement post.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

### Security:

* Add `cooldown` to delay newly published gem. Pull request [#9576](https://github.com/ruby/rubygems/pull/9576) by hsbt
* Add `cooldown` to delay newly published gem. Pull request [#9576](https://github.com/ruby/rubygems/pull/9576) by hsbt. See [Cool down before you install]({% post_url 2026-06-03-cooldown-let-new-gems-be-vetted %}) for what it does and how to turn it on.
@hsbt hsbt merged commit b27f035 into master Jun 3, 2026
3 checks passed
@hsbt hsbt deleted the cooldown-announcement branch June 3, 2026 03:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants