A critique of dependency cooldowns for supply-chain security, arguing that they shift risk onto others and that package-index upload queues would be a better default. [calpaterson.com] Continue reading...