Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
833
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

Bundler 4.0.18, released with RubyGems 4.0.18 on August 5, 2026, extends its opt-in dependency cooldown feature to the bundle lock and bundle cache commands, addressing an earlier inconsistency in which those commands could not accept the --cooldown override flag. Introduced in Bundler 4.0.13, cooldown uses RubyGems.org release metadata to exclude gem versions published within a configured number of days, helping projects delay adoption of newly released packages while allowing an immediate one-run override with --cooldown 0 for cases such as urgent security fixes. The update ensures automated lockfile-generation and gem-caching workflows can override the delay when necessary, while also adding documentation and a regression test confirming that cooldown evaluates gem names and versions without considering platform-specific builds. Bundler 4.0.18 additionally warns users when duplicate source declarations specify conflicting cooldown values, and the feature remains a client-side, optional supplement to registry protections such as publishing validation, two-factor authentication, and trusted publishing.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.