Remix.run Logo
outloudvi 4 hours ago

After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions:

- Independent security companies are scanning the packages (be careful if the project is depending on some no-so-popular packages)

- Maintainers react promptly (it would be nonsense if people need to cooldown for 21 days because people may have 21-day vacations)