We should all be using dependency cooldowns
Mood
informative
Sentiment
positive
Category
tech_discussion
Key topics
Dependency Management
Software Development
Best Practices
Discussion Activity
Light discussionFirst comment
2d
Peak period
1
Day 2
Avg / period
1
Based on 2 loaded comments
Key moments
- 01Story posted
Nov 21, 2025 at 9:50 AM EST
2d ago
Step 01 - 02First comment
Nov 23, 2025 at 2:03 AM EST
2d after posting
Step 02 - 03Peak activity
1 comments in Day 2
Hottest window of the conversation
Step 03 - 04Latest activity
Nov 23, 2025 at 1:34 PM EST
13h ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
All the security theatre!
False urgency is red flag when it comes to emails and sms.. I dont see why people don't see the same when it comes to dependency alerts.
The vast vast majority of alerts are totally useless, when it comes to your actual deployed system, unexploitable and irrelevant.
Rushing to update causes make-work, churn and loss of focus on the real.
Don't get me wrong, I love secure systems, but dependency theatre doesn't make it.
Very very occasionally, you'll get a high priority signal, and then yes act on it immediately. Your deployment systems should be designed so that this is just another release. No expedited short cuts, just another day.
Reducing dependencies, defense in depth, validation, type-safe, null-safe languages etc all good.. endless dependabot PRs with no understanding of the reason or impact, bad.
I delay the use of updated software by a week, and anyone that doesn't takes the risk. Therefore I, the user of the cooldown, enjoys reduced risk at the expense of everyone not implementing a cooldown.
If everyone simply delays their updates, then there is nobody to suffer an attack which notifies users of the cooldown (in this case, everybody).
The blog post makes the argument that the vendors are incentivized to discover these attacks in this time, but that's an entirely different argument and if that were true, they would already be doing that.
In fact, auditing updates for vulnerabilities is the general solution. The whole appeal of the cooldowns is that you don't have to do that - the cost is that it's a zero-sum game reliant on the suffering of those less wise.
257 more comments available on Hacker News
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.