4 ms·
This could be controlled by npm. Client ask for available versions anyway. If package is security fix then it can be made available instantly. But this delay gi
by Chyzwar 6mo ago
This could be controlled by npm. Client ask for available versions anyway. If package is security fix then it can be made available instantly. But this delay gives time for security scanners and time to notify maintainers that package was published.
- mcintyre1994 6mo agoThen the malicious packages would always be published as a security fix.