| ▲ | cpburns2009 5 hours ago | |
I don't disagree with this take. But I'm not going to risk installing a package uploaded 1 hour ago considering all of the compromises this year. I think a cooldown period is prudent to let the automated security scanners to do their thing. | ||
| ▲ | sudobash1 4 hours ago | parent [-] | |
It also includes time to allow discovering of compromised accounts. If the owner of a popular package is hacked, this gives the owner a week to raise alarms about this. | ||