Research investigation R0916 / comparison

After RubyGems: Can Major Package Registries Make Agent-Scale Publishing Reviewable Before Release?

All three registries document workflow-bound, short-lived publishing authority, but that control does not itself require human review. In the reviewed public materials, npm documents a registry-native staged path with a maintainer 2FA release gate; RubyGems and PyPI can publish directly from trusted workflows unless maintainers add an external CI approval rule.

Archived snapshotv1Sep 19, 2026
Verified observations
6

6 measured fields

Supported claims
9

9 material findings

Cited sources
12

12 primary or authoritative

Research score
85

Automated topic and evidence score

Interactive figureAfter RubyGems: Can Major Package Registries...
CSV JSON
Data status1 verified record across 1 period

Snapshot only. There is not enough history to claim a trend yet.

Verified observationHover or focus any mark for exact valuesLast updated Sep 19, 2026

Version ledger

Frozen public editions

Each edition preserves the records, method, sources, and downloads available at publication time.

  1. v1 / latestSep 19, 20266 records / 12 sources

    Initial public snapshot with 6 records and 12 cited sources.

Coverage note

The comparison is bounded to supplied public records available through September 16, 2026. It covers RubyGems, npm, and PyPI documentation and one RubyGems incident disclosure; it does not assess undisclosed controls, operational effectiveness, or CI-provider settings beyond what the registry materials describe.

Dataset ID
spd:after-rubygems-can-major-package-registries-make-agent-scale-publishing-reviewable-before-release-9d7c6e22
Stable URL
/research/after-rubygems-can-major-package-registries-make-agent-scale-publishing-reviewable-before-release-9d7c6e22
Version
v1
Coverage
2026-09-16
Records
6
Fields
7
Updated

Read the data

The records behind the figure

CSV JSON
After RubyGems: Can Major Package Registries Make Agent-Scale Publishing Reviewable Before Release? data records
EntityMetricValueUnitObservedSourceTransform
npmdocumented possible token-revocation delayup to one hourhour2026-09-16https://docs.npmjs.com/revoking-access-tokens
RubyGemsdocumented signup limit100 requests per 10 minutes per client IPrequests/10 minutes/IP2026-09-16https://guides.rubygems.org/rubygems-org-rate-limits
RubyGemsdocumented successful gem-push limit400 requests per hourrequests/hour2026-09-16https://guides.rubygems.org/rubygems-org-rate-limits
npmmaximum trusted publishers per packageup to 10configurations/package2026-09-16https://docs.npmjs.com/trusted-publishers
PyPImaximum Trusted Publishing token lifetimeno more than 15 minutes after authorizationminutes2026-09-16https://docs.pypi.org/trusted-publishers/security-model
RubyGemspackages yanked in May spam campaignmore than 500packages, lower bound2026-09-11https://blog.rubygems.org/2026/09/11/update-may-spam-publishing-campaign.html

Measurement technique

How to read this report

  1. 01Evidence matrix plan: normalize official public documentation into identity binding, credential lifetime, direct release, staging, human approval, provenance, registration limits, publish limits, revocation, account or incident records, and public incident disclosures.
  2. 02Classify each control as documented availability, registry-native enforcement, external workflow configuration, or not documented in the reviewed materials.
  3. 03Keep release provenance separate from incident forensics: a workflow receipt does not establish a complete incident record.
  4. 04Use only the supplied official RubyGems, npm, and PyPI evidence, checked through September 16, 2026.
Next report / 01AI Model Economics Index All research reports
YOUR READING SPACE

Notifications