Package update cooldowns as a supply-chain defense
DavidWells · x · 2026-07-20
A practical defense against software supply-chain attacks: enforce package update cooldowns across ecosystems.
The shared resource argues that many prominent supply-chain compromises are exploited quickly but also detected quickly, and that a 3-day cooldown would have blocked most of the cited cases. The screenshot cites an analysis of ten major supply-chain attacks: eight had exploitation windows under a week, and all but one lasted under two weeks.
It also shows concrete ecosystem support, such as uv adding a built-in cooldown feature in v0.9.17, with native relative-duration syntax like uv pip install --exclude-newer '3 days' foo.
More from Infra
- China’s AI arms race is increasingly defined by chips, data centers, and open models — BenBajarin · 2026-07-22
- Agent search bottlenecks are now about variance, not raw latency — rohanpaul_ai · 2026-07-22
- Gavin Baker argues Nvidia may be one of open source AI’s biggest supporters — GavinSBaker · 2026-07-22
- AI Power Demand Exposes US Energy Gap, Urging Shift from Scarcity to Abundance — bradneuberg · 2026-07-22
- Gavin Baker says Nvidia’s $630B figure would be system revenue, not all Nvidia’s — GavinSBaker · 2026-07-22
- A Firecracker-based platform says it can host 6,000 AI agents on one 256 GB server — maritime_sh · 2026-07-22