Package update cooldowns as a supply-chain defense
DavidWells · x · 2026-07-20
A practical defense against software supply-chain attacks: enforce package update cooldowns across ecosystems.
The shared resource argues that many prominent supply-chain compromises are exploited quickly but also detected quickly, and that a 3-day cooldown would have blocked most of the cited cases. The screenshot cites an analysis of ten major supply-chain attacks: eight had exploitation windows under a week, and all but one lasted under two weeks.
It also shows concrete ecosystem support, such as uv adding a built-in cooldown feature in v0.9.17, with native relative-duration syntax like uv pip install --exclude-newer '3 days' foo.
More from Infra
- LLM Serving Metrics Thread: Why TPOT and Uptime Make or Break User Experience — abhijithneil · 2026-09-11
- PlanetScale launches sharded Postgres: 768 servers acting as one, 1PB scale — dhruv2038 · 2026-09-11
- Can a 7900 XTX 24GB run Qwen locally? Reddit seeks ROCm tok/s benchmarks — thenomadexplorerlife · 2026-09-11
- RTK Terminal Compression Cuts Tokens but Leaves Your AI Coding Bill Unchanged — Bartaseth · 2026-09-11
- SF Compute founder: buying compute is 'an absolutely awful experience' right now — IgorCarron · 2026-09-11
- SmolVM open-sources persistent computer infrastructure for agents that outlive chat sessions — aniketmaurya · 2026-09-11