Hacker News new | ask | show | jobs
by detaro 3079 days ago
They allow deletion of packages for 24 hours without staff involvement, there is nothing said about a time limit on republishing after deletion?
1 comments

From the response steps:

> Our first action, which began immediately after the incident concluded, was to implement a 24-hour cooldown on republication of any deleted package name.

But they also have a policy of replacing deleted package names with placeholders, which was not currently enforced for spam-deletions. The cooldown should give them 24 hours to discover any remaining holes in that policy.
Oops, missed that part. Guess the logic is that for spam-packages, there isn't going to be anyone relying on them and it would be a waste of namespace space to allow spammers to fill it up?
Yes, and there are dozens of spam packages registered (and deleted) every day.