| ▲ | saghm 4 hours ago | |
Isn't this what alpha/beta/RC releases are for, ensuring that there are no issues before a general release? I just don't get ecosystem has decided to use client-side configurations for this rather than just marking the releases in the ways that already exist. | ||
| ▲ | pixl97 4 hours ago | parent | next [-] | |
When the attacker gets your npm/gh credentials they just publish a new 'full' release making your idea worthless. | ||
| ▲ | normie3000 4 hours ago | parent | prev [-] | |
If it helps, think of cooldown periods as a way to do staged rollouts. | ||