| ▲ | outloudvi 4 hours ago | |
After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions: - Independent security companies are scanning the packages (be careful if the project is depending on some no-so-popular packages) - Maintainers react promptly (it would be nonsense if people need to cooldown for 21 days because people may have 21-day vacations) | ||