Security · 4h ago
NPM's release cooldown called security theater by critics
A developer argues NPM's mandatory 72-hour cooldown for package updates fails to prevent supply-chain attacks. The policy delays legitimate releases while offering no real protection against malicious actors. Critics say it adds friction without addressing root causes like weak authentication or typosquatting.
Meridian48 take
The critique is valid: cooldowns treat symptoms, not the disease—NPM needs stronger verification, not just delays.
npmsupply-chain-security