3 ms·
After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions: - Independent security compa
by outloudvi 2mo ago
After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions:
- Independent security companies are scanning the packages (be careful if the project is depending on some no-so-popular packages)
- Maintainers react promptly (it would be nonsense if people need to cooldown for 21 days because people may have 21-day vacations)