I used to advocate keeping all your dependencies in-house on servers you update on your own schedule, on the argument that if your devs are pulling random shit from public repositories you're already in trouble, but I didn't know this "dependency cooldown" idea not only existed but... is already out there, and available for nearly free?

I'm sort of curious what the game-theory model of this looks like as uptake increases but it sure looks like a good idea.

blog.yossarian.net/2025/11/21/

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/mhoye/statuses/115588280607269974 on your instance and quote it. (Note that quoting is not supported in Mastodon.)