Post #3163978
2026-06-07 10:03 UTC
Replies (1)
-
@pointlessone@status.pointless.one 2026-06-07 10:29
@janpet@ruby.social 1) It does but the research is implicit. If no one even looks cooldown will expire eventually. There's way too many packages to be examined by security researchers. And security research is not how most compromised packages are detected. xz story is much more common: a regular user (i.e. not a security researcher) investigates some weird behaviour. 2) cooldowns do not solve this issue. Cooldowns let someone else install a package before you. It somewhat limits impact on the ecosystem level but on the individual org/user level it doesn't do anything. You get infected when you install the package. The whole premise is that the first affected will raise the issue and it will get addressed within the cooldown period. In effect, cooldowns are antisocial. They don't prevent installation of a compromised package, they only let someone else be affected first. And hope they will notice and escalate the issue before it's your turn to install the package. The only good thing about cooldowns is that they're very low effort.