TUESDAY, JULY 21, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 4h ago

NPM's release cooldown called security theater by critics

By Meridian48 News Desk · Summarised from Hacker News ·

A developer argues NPM's mandatory 72-hour cooldown for package updates fails to prevent supply-chain attacks. The policy delays legitimate releases while offering no real protection against malicious actors. Critics say it adds friction without addressing root causes like weak authentication or typosquatting.

Meridian48 take
The critique is valid: cooldowns treat symptoms, not the disease—NPM needs stronger verification, not just delays.
Read the full reporting
NPM's release cooldown is security theater →
Hacker News
npmsupply-chain-security
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan