The problem with this approach is, it only works as long as someone does the checking. In practice everyone turns on 'safe update channel' and nobody actually tests the bleeding edge, ten days elapse, and the malicious code flows into the 'safe channel'.
It is like sending for help in a first-aide situation, you need to point at someone specifically, make eye contact and say "YOU! go get help" if you just shout 'someone get help' and go back to recuse breathing or whatever you're occupied with everyone will stand around on-looking assuming someone else is doing something.
I love Ruby, it is an elegant language and it has made great performance gains in resent years, but but bundler and the drama around rubygems is a really problem, for anyone trying to make commercial use of it. I hate to say it but if Ruby is going to survive it probably needs to find another major patron besides Shopify, that is willing take some ownership and investment in the outside the standard library supply chain. Bandages like this are not going to cut it, and pure community lead effort isn't likely to be able to keep up with the evolving threat landscape. Unless your project is Linux, Samba, Bind, Apache, level deployment scale it just does not work with the degree of attack surface something like package/module repository offers.