Hacker News new | ask | show | jobs
by Chyzwar 79 days ago
This could be controlled by npm. Client ask for available versions anyway. If package is security fix then it can be made available instantly. But this delay gives time for security scanners and time to notify maintainers that package was published.
1 comments

Then the malicious packages would always be published as a security fix.