←back to thread

1369 points universesquid | 1 comments | | HN request time: 0s | source
Show context
dist-epoch ◴[] No.45170028[source]
Given that most of these kind of attacks are detected relatively quickly, NPM should implement a feature where it doesn't install/upgrade packages newer than 3 days, and just use the previous version.
replies(3): >>45170138 #>>45170232 #>>45170382 #
1. jowea ◴[] No.45170232[source]
What if the latest patch is (claiming to be) a security fix? Then that's 3 days of more insecurity.