Many malicious packages get caught within a few days or even a few hours. Your org rarely needs a dependency version released that recently. A one week cooldown offers a strong security ROI with minimal developer friction.
Malicious Python and JavaScript deps have dominated this year's supply chain news cycle, but how many of y'all still have pinning GitHub Actions on your to do list?
Hereโs how I did this org-wide at Semgrep.