NPM's release cooldown is security theater
The author argues that the recent trend of 'release cooldowns' in package managers like npm and pnpm is ineffective security theater. Instead of waiting for community vetting, the author suggests that developers should adopt active scanning and manual research to identify malicious code.
Why it matters
It challenges current industry-standard security practices in software supply chain management, advocating for more proactive developer-led security measures.
Due to many ecosystem attack incidents, package managers (and packagers, and managers) are apparently falling in love with cooldowns these days ( npm , pnpm , yarn and so on). As a result, their upstream registry is time-gated for some 7 days or 24 hours.
Sounds sweet as honey. Except that it is not going to work. I'll say it's not honey, but a honeypot that traps.
Some are waiting for the community to "vet" the package before installing it. However, people don't know what's the appropriate cooldown time (e.g. 7 days for yarn, 3 days for pnpm). Also, a spoiler: people have no idea who would vet, either.
The implicit assumption is that someone out there (in the community ) will:
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in