Hacker News new | ask | show | jobs
by saghm 11 days ago
Isn't this what alpha/beta/RC releases are for, ensuring that there are no issues before a general release? I just don't get ecosystem has decided to use client-side configurations for this rather than just marking the releases in the ways that already exist.
2 comments

When the attacker gets your npm/gh credentials they just publish a new 'full' release making your idea worthless.
If it helps, think of cooldown periods as a way to do staged rollouts.