Slacker News Slacker News logo featuring a lazy sloth with a folded newspaper hat
  • top
  • new
  • show
  • ask
  • jobs
Library
← Back to context

Comment by kazinator

8 days ago

If everyone simultaneously imposes the same cooldown period for picking up a new dependency, that's as good as nothing at all. The malicious change just sits there for 20 days (or whatever) with nobody looking at it or running it. Then it hits everywhere at once.

However, a randomized cooldown may be a good idea. To borrow a pandemic term, it flattens the curve.

0 comments

kazinator

Reply

No comments yet

Contribute on Hacker News ↗

Slacker News

Product

  • API Reference
  • Hacker News RSS
  • Source on GitHub

Community

  • Support Ukraine
  • Equal Justice Initiative
  • GiveWell Charities