| ▲ | CGamesPlay 3 hours ago | |
The packages that are actually compromised are yanked, but I assume you're talking about a scenario more like log4shell. In that case, you can just disable the config to install the update, then re-enable in 7 days. Given that compromised packages are uploaded all the time and zero-day vulnerabilities are comparatively less common, I'd say it's the right call. | ||
| ▲ | robertfw an hour ago | parent [-] | |
`uv` has per-package overrides, I imagine there may be similar in other managers | ||