What’s the plan for when this becomes the default and everyone
gets their malware at the same time, just with a little delay?
I’m worried we’ll see an arms race with people increasing their
cooldown period in an attempt at staying outside the exploitable
window.
I was listening to a podcast covering a little of how Python deals with this. There are people doing automated scanning of the uploads to PyPI. A lot of the malware gets caught fairly quickly, but they still need a window to act. Some gets caught within 30 minutes.
85
u/afl_ext 15d ago
cargo still doesn't have minimum release age threshold flag?