Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
Blog post from Socket
Bundler 4.0.18, released with RubyGems 4.0.18 on August 5, 2026, extends its opt-in dependency cooldown feature to the bundle lock and bundle cache commands, addressing an earlier inconsistency in which those commands could not accept the --cooldown override flag. Introduced in Bundler 4.0.13, cooldown uses RubyGems.org release metadata to exclude gem versions published within a configured number of days, helping projects delay adoption of newly released packages while allowing an immediate one-run override with --cooldown 0 for cases such as urgent security fixes. The update ensures automated lockfile-generation and gem-caching workflows can override the delay when necessary, while also adding documentation and a regression test confirming that cooldown evaluates gem names and versions without considering platform-specific builds. Bundler 4.0.18 additionally warns users when duplicate source declarations specify conflicting cooldown values, and the feature remains a client-side, optional supplement to registry protections such as publishing validation, two-factor authentication, and trusted publishing.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.