| ▲ | datakan an hour ago | |
There is a big difference between 3 days when someone may be sick or traveling and not looking and 30 which aligns better with 99% of scenarios this may be an issue with. 3 days is absurd. Even password apps with kill switches will default to 7 days. Cyber attacks will frequently happen on a Friday just for this scenario, they anticipate no ones looking over the weekend. | ||
| ▲ | tredre3 28 minutes ago | parent [-] | |
And 365 days probably aligns with 100% of scenarios. It doesn't mean it's a good idea, because the longer the delay is the more downsides you also get. Blocking a maintainer from pushing updates for a full month after changing their e-mail would be obviously absurd. So Github would have to add a way of enabling maintainers to super-uper-duper confirm the change and cut the delay short. Which is likely not currently possible, hence starting with a shorter delay. | ||