|
|
|
|
|
by outloudvi
11 days ago
|
|
After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions: - Independent security companies are scanning the packages (be careful if the project is depending on some no-so-popular packages) - Maintainers react promptly (it would be nonsense if people need to cooldown for 21 days because people may have 21-day vacations) |
|