← Back to context

Comment by Barbing

4 hours ago

Would be bad for software/progress I guess but, got me thinking of if we had an expectation a dev would post an update checksum/hash, then follow it up a day later with the update itself...

(well maybe that leads to kidnappings idk)

edit - heh, sibling comment on package manager-level must be much smarter

> Would be bad for software/progress I guess but

We all need to slow down and get some perspective. “Progress” doesn’t mean “rush everything and do it now now now”. Advancements should be slow, methodical, considered. That’s a good thing, not a weakness.

I fail to see how this isn't a simple cool down with more steps. It doesn't seem to add anything to the security posture of the package/update