| ▲ | tadfisher 2 hours ago | |
There are so many ways to self-host package repos that "immediate availability" to the wider npm-using public is a non-issue. Exceptions to quarantine rules just invites attackers to mark malicious updates as security patches. If every kind of breakage, including security bugs, results in a 2-3 hour wait to ship the fix, maybe that would teach folks to be more careful with their release process. Public software releases really should not be a thing to automate away; there needs to be a human pushing the button, ideally attested with a hardware security key. | ||