Package Managers Need to Cool Down (opens in new tab)
Today's LiteLLM supply chain attack inspired me to revisit the idea of dependency cooldowns, the practice of only installing updated dependencies once they've been out in the wild for a …
Read the original article