Article may be outdated

This article is 73 days old. Some details may have changed since publication.

Hacker News·3 min read·medium

NPM's release cooldown is security theater

O
outloudvi
✦AI Summary

The author argues that the recent trend of 'release cooldowns' in package managers like npm and pnpm is ineffective security theater. Instead of waiting for community vetting, the author suggests that developers should adopt active scanning and manual research to identify malicious code.

Why it matters

It challenges current industry-standard security practices in software supply chain management, advocating for more proactive developer-led security measures.

✦Dive DeeperCreate a free account to unlock

Due to many ecosystem attack incidents, package managers (and packagers, and managers) are apparently falling in love with cooldowns these days ( npm , pnpm , yarn and so on). As a result, their upstream registry is time-gated for some 7 days or 24 hours.

Sounds sweet as honey. Except that it is not going to work. I'll say it's not honey, but a honeypot that traps.

Some are waiting for the community to "vet" the package before installing it. However, people don't know what's the appropriate cooldown time (e.g. 7 days for yarn, 3 days for pnpm). Also, a spoiler: people have no idea who would vet, either.

The implicit assumption is that someone out there (in the community ) will:

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in