Hacker News new | ask | show | jobs
by collinmanderson 11 days ago
> no cooldown (or a much smaller countdown) for security fixes.

A supply chain attack would likely able to publish a "security" release just as easily as a normal release, so I don't think that would help much.