Fast upgrades
Fast upgrades
Posted Apr 22, 2026 15:53 UTC (Wed) by mathstuf (subscriber, #69389)In reply to: Fast upgrades by ju3Ceemi
Parent article: Dependency-cooldown discussions warm up
If you attach a CVE report (or equivalent) to an upload, this makes sense to me. This (probably?) involves a lot more work than just stealing a secret key. Additionally, if something *explicitly* requests the version, it should be made available (so that I can update dependent packages immediately without having to wait N days per dependency depth to update an entire stack).
