flâneur — a map of the web's best reading

We should all be using dependency cooldowns

blog.yossarian.net · 1,112 words · saved by 1 readers

TL;DR: Dependency cooldowns are a free, easy, and incredibly effective way to mitigate the large majority of open source supply chain attacks. More individual projects should apply cooldowns (via tools like Dependabot and Renovate) to their dependencies, and packaging ecosystems should invest in first-class support for cooldowns directly in their package managers. Some resources for adding cooldowns: “Supply chain security” is a serious problem. It’s also seriously overhyped, in part because dozens of vendors have a vested financial interest in convincing your that their framing of the underlying problem1 is (1) correct, and (2) worth your money. What’s consternating about this is that most open source supply chain attacks have the same basic structure: An attacker compromises a popular open source project, typically via a stolen credential or CI/CD vulnerabilty (such as “pwn requests” in GitHub Actions). The attacker introduces a malicious change to the project and uploads it somewher

We should all be using dependency cooldowns ENOSUCHBLOG Programming, philosophy, pedaling. Home Tags Series Favorites Archive Main Site TILs We should all be using dependency cooldowns Nov 21, 2025 Tags: oss , security TL;DR : Dependency cooldowns are a free, easy, and incredibly effective way to mitigate the large majority of open source supply chain attacks. More individual projects should apply cooldowns (via tools like Dependabot and Renovate) to their dependencies, and packaging ecosystems should invest in first-class support for cooldowns directly in their package managers. Some resource

Explore this link on the map →

saved by

related reading