We should all be using dependency cooldowns
TL;DR: Dependency cooldowns are a free, easy, and incredibly effective way to mitigate the large majority of open source supply chain attacks. More individual projects should apply cooldowns (via tools like Dependabot and Renovate) to their dependencies, and packaging ecosystems should invest in first-class support for cooldowns directly in their package managers. Some resources for adding cooldowns: “Supply chain security” is a serious problem. It’s also seriously overhyped, in part because dozens of vendors have a vested financial interest in convincing your that their framing of the underlying problem1 is (1) correct, and (2) worth your money. What’s consternating about this is that most open source supply chain attacks have the same basic structure: An attacker compromises a popular open source project, typically via a stolen credential or CI/CD vulnerabilty (such as “pwn requests” in GitHub Actions). The attacker introduces a malicious change to the project and uploads it somewher
We should all be using dependency cooldowns ENOSUCHBLOG Programming, philosophy, pedaling. Home Tags Series Favorites Archive Main Site TILs We should all be using dependency cooldowns Nov 21, 2025 Tags: oss , security TL;DR : Dependency cooldowns are a free, easy, and incredibly effective way to mitigate the large majority of open source supply chain attacks. More individual projects should apply cooldowns (via tools like Dependabot and Renovate) to their dependencies, and packaging ecosystems should invest in first-class support for cooldowns directly in their package managers. Some resource
Explore this link on the map →saved by
related reading
- State of DevSecOps | Datadogdatadoghq.com
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Mediummedium.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Software Supply Chain Security (Part 1)softwareanalyst.substack.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / Xx.com
- The Node-IPC Incidentnotes.ekzhang.com
- Open source in cybersecurity: a deep diveventureinsecurity.net
- Security incident disclosure — July 2026huggingface.co
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com