We should all be using dependency cooldowns

118 points by yossarian


technomancy

Sounds like language-level packagers are starting to realize that it turns out distros had some good ideas after all.

mk12

If everyone used dependency cooldowns wouldn’t they also become less effective?

lcapaldo

Are non malicious latent vulnerabilities less common than active supply chain attacks? Is there a tension between cooling down and getting the latest version without the vulnerability? I can’t imagine you would want to exempt fixes from the cooldown, that just incentives the attacks to target the exempted releases.