Last week, the continuous integration pipeline I set up failed because a package that I had locked three weeks ago was no longer resolving in the same manner on my local machine. The solution? Just wait for 72 hours. Because that seems to be the approach to security these days. 🙄

The new gospel of waiting

Security teams think they have found the answer to supply-chain attacks: Time. Here's a simple suggestion: don't install a package as soon as it's released. Wait 72 hours so that someone else can discover the poison. The entire ecosystem quickly adopted it. In July 2026, GitHub implemented a default 72-hour cooldown for non-security Dependabot updates. Both pnpm and Yarn implemented minimum package age restrictions in September 2025. npm v11.10.0 added min-release-age in February 2026. Additionally, PyPI also took measures to protect against future typosquatting attacks. They decided to block the upload of new files to any release that was older than 14 days. Everything seems reasonable. It seems like adults are finally starting to consider the risk in the supply chain.

The math doesn't math

The unspoken truth is that... Most of the malware you are trying to avoid is eliminated even before your cooldown begins. Consider the major attacks in 2025/2026: Axios, s1ngularity, Shai-Hulud. All malicious packages were found and removed within a median of 14 hours. This window of 72 hours is sheltering you from a danger that would have perished already, by the 15th hour. You are essentially paying three days of opportunity cost to be protected from a fire that your sprinklers have already extinguished.