💎 The Gem Cooperative is testing dependency cooldowns at the registry level, delaying access to newly published gems rather than relying on client tooling. An interesting infrastructure experiment to reduce exposure to malicious #Ruby gems during supply chain attacks:

https://socket.dev/blog/gem-coop-tests-dependency-cooldowns

gem.coop Tests Dependency Cooldowns as Package Ecosystems Mo...

gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.

Socket