I used to advocate keeping all your dependencies in-house on servers you update on your own schedule, on the argument that if your devs are pulling random shit from public repositories you're already in trouble, but I didn't know this "dependency cooldown" idea not only existed but... is already out there, and available for nearly free?
I'm sort of curious what the game-theory model of this looks like as uptake increases but it sure looks like a good idea.
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
