Remix.run Logo
pixl97 4 hours ago

>think this is eventually becoming some type of pointless arms race, as cooldown does not act actively towards reducing ecosystem attacks.

The nature of some of these attacks, it does. If your developers machine with publishing rights gets rooted a cool down makes credential gathering attacks via script in npm so very much harder it's not even funny.

In some of the recent supply chain attacks the entire fiasco was only a few hours long, but in that time tens of hundreds of thousands of credentials may have been stolen.

One day timers have the weakness of weekends and holidays reducing the number of eyes/systems seeing the issue.

outloudvi 4 hours ago | parent [-]

After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions:

- Independent security companies are scanning the packages (be careful if the project is depending on some no-so-popular packages)

- Maintainers react promptly (it would be nonsense if people need to cooldown for 21 days because people may have 21-day vacations)