Live
Black Hat USADark ReadingBlack Hat AsiaAI BusinessCrowdStrike, Cisco and Palo Alto Networks all shipped agentic SOC tools at RSAC 2026 — and all three missed the same gapVentureBeat AIMassachusetts Sen. Ed Markey is putting AV firms on blast for using human staffersFast Company TechGoogle's Vertex AI Has an Over-Privileged Problem - Dark ReadingGNews AI GoogleThe Iron Man Model Of Legal AI - Above the LawGNews AI legalAI law in Canada is evolving through familiar principles - Canadian Lawyer MagGNews AI legalHartford HealthCare and K Health Launch PatientGPT to Integrate AI with Medical Records - HIT ConsultantGNews AI healthcareNew in Bioethics Briefings: AI in Healthcare - The Hastings Center for BioethicsGNews AI healthcareThe New Duet: AI as Creative MediumDev.to AIThree Things Had to Align: The Real Story Behind the LLM RevolutionDev.to AIMore money poured into AI processors and data centers - jonpeddie.comGNews AI KoreaInfinite AI Video, 4K Images, Realtime Videos, DeepSeek Breakthrough, Google’s Quantum Leap: AI NEWS [0f434a] - MshaleGNews AI GoogleOpenAI raises $122bn in new funding amid AI boom - The GuardianGoogle News: OpenAIBlack Hat USADark ReadingBlack Hat AsiaAI BusinessCrowdStrike, Cisco and Palo Alto Networks all shipped agentic SOC tools at RSAC 2026 — and all three missed the same gapVentureBeat AIMassachusetts Sen. Ed Markey is putting AV firms on blast for using human staffersFast Company TechGoogle's Vertex AI Has an Over-Privileged Problem - Dark ReadingGNews AI GoogleThe Iron Man Model Of Legal AI - Above the LawGNews AI legalAI law in Canada is evolving through familiar principles - Canadian Lawyer MagGNews AI legalHartford HealthCare and K Health Launch PatientGPT to Integrate AI with Medical Records - HIT ConsultantGNews AI healthcareNew in Bioethics Briefings: AI in Healthcare - The Hastings Center for BioethicsGNews AI healthcareThe New Duet: AI as Creative MediumDev.to AIThree Things Had to Align: The Real Story Behind the LLM RevolutionDev.to AIMore money poured into AI processors and data centers - jonpeddie.comGNews AI KoreaInfinite AI Video, 4K Images, Realtime Videos, DeepSeek Breakthrough, Google’s Quantum Leap: AI NEWS [0f434a] - MshaleGNews AI GoogleOpenAI raises $122bn in new funding amid AI boom - The GuardianGoogle News: OpenAI

Package Managers Need to Cool Down

Simon Willison BlogMarch 24, 20262 min read0 views
Source Quiz

<p><strong><a href="https://nesbitt.io/2026/03/04/package-managers-need-to-cool-down.html">Package Managers Need to Cool Down</a></strong></p> Today's <a href="https://simonwillison.net/2026/Mar/24/malicious-litellm/">LiteLLM supply chain attack</a> inspired me to revisit the idea of <a href="https://simonwillison.net/2025/Nov/21/dependency-cooldowns/">dependency cooldowns</a>, the practice of only installing updated dependencies once they've been out in the wild for a few days to give the community a chance to spot if they've been subverted in some way.</p> <p>This recent piece (March 4th) piece by Andrew Nesbitt reviews the current state of dependency cooldown mechanisms across different packaging tools. It's surprisingly well supported! There's been a flurry of activity across major pac

24th March 2026 - Link Blog

Package Managers Need to Cool Down. Today's LiteLLM supply chain attack inspired me to revisit the idea of dependency cooldowns, the practice of only installing updated dependencies once they've been out in the wild for a few days to give the community a chance to spot if they've been subverted in some way.

This recent piece (March 4th) piece by Andrew Nesbitt reviews the current state of dependency cooldown mechanisms across different packaging tools. It's surprisingly well supported! There's been a flurry of activity across major packaging tools, including:

  • pnpm 10.16 (September 2025) — minimumReleaseAge with minimumReleaseAgeExclude for trusted packages

  • Yarn 4.10.0 (September 2025) — npmMinimalAgeGate (in minutes) with npmPreapprovedPackages for exemptions

  • Bun 1.3 (October 2025) — minimumReleaseAge via bunfig.toml

  • Deno 2.6 (December 2025) — --minimum-dependency-age for deno update and deno outdated

  • uv 0.9.17 (December 2025) — added relative duration support to existing --exclude-newer, plus per-package overrides via exclude-newer-package

  • pip 26.0 (January 2026) — --uploaded-prior-to (absolute timestamps only; relative duration support requested)

  • npm 11.10.0 (February 2026) — min-release-age

pip currently only supports absolute rather than relative dates but Seth Larson has a workaround for that using a scheduled cron to update the absolute date in the pip.conf config file.

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by AI News Hub · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

More about

releaseupdatereview

Knowledge Map

Knowledge Map
TopicsEntitiesSource
Package Man…releaseupdatereviewgithubSimon Willi…

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 134 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!

More in Releases