|
|
|
|
|
by jamesnorden
276 days ago
|
|
I think the cooldown approach would make this type of attack have practically no impact anymore, if nobody ever updates to a newly published package version until, say, 2-3 days have gone by, surely there will be enough time for owner of the package to notice he got pwnd. |
|
https://docs.renovatebot.com/configuration-options/#minimumr...