Become a Patron!

Dependency cooldowns turn you into a free-rider

Status
Not open for further replies.

VUBot

Staff member
Diamond Contributor
ECF Refugee
Vape Media
A critique of dependency cooldowns for supply-chain security, arguing that they shift risk onto others and that package-index upload queues would be a better default. [calpaterson.com]

Continue reading...
 
Status
Not open for further replies.

VU Sponsors

Top