Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
yossarian (1.3.6.1.4.1.55738)
yossarian (1.3.6.1.4.1.55738)
@yossarian@infosec.exchange  ·  activity timestamp 3 months ago

We should all be using dependency cooldowns

https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns

#security #oss

#oss #security
  • Copy link
  • Flag this post
  • Block
Seth Larson
Seth Larson
@sethmlarson@mastodon.social  ·  activity timestamp 3 months ago

@yossarian This is an awesome blog post, especially the data section! I had no idea Dependabot supported a cooldown configuration like that... 👀 Makes me want to have this as a feature of package installers during resolution.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.37 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct