[HN Gopher] Package Managers Need to Cool Down
       ___________________________________________________________________
        
       Package Managers Need to Cool Down
        
       Author : zdw
       Score  : 6 points
       Date   : 2026-03-05 00:21 UTC (2 days ago)
        
 (HTM) web link (nesbitt.io)
 (TXT) w3m dump (nesbitt.io)
        
       | jauntywundrkind wrote:
       | If everyone only starts using a package after 7d, it feels like
       | it just means we don't find out about problematic packages until
       | 7d later . The reason 7d works is because it is the "don't go
       | first" effect (I assert with no evidence). But if everyone does
       | the same delay, there's no longer a benefit to you delaying. This
       | feels like a prisoners dilemma of no one upgrading.
       | 
       | I do think there is some sense in having some cool down.
       | Automated review systems having some time to sound alarms would
       | be good.
       | 
       | I'm not sure what the reporting mechanisms look like for various
       | ecosystems. Being able to declare that there should be a hold is
       | Serious Business, and going through with a hold or removal is a
       | very human costly decision to make for repo maintainers.
       | 
       | Ideally I'd like to see something like atprotocol, where
       | individuals can create records on their PDS's that declare
       | dangers. This can form a reputation system, that disincentivizes
       | bad actors, and which can let anyone on the net quickly see
       | incoming dangers, in a distributed fashion, real time.
       | 
       | (Hire me, I'll build it.)
        
       | mpalmer wrote:
       | Surprised not to see nix mentioned in connection with this topic!
       | 
       | If you use nix (especially nix flakes), this consideration falls
       | out naturally from the nixpkgs repository reference (SHA, branch,
       | etc) you choose to track. Nixpkgs has various branches for
       | various appetites for the "cutting edge".
        
       ___________________________________________________________________
       (page generated 2026-03-07 23:00 UTC)