logoalt Hacker News

arionmilestoday at 4:30 AM1 replyview on HN

Valid point. We have minimum age requirements set on some rules to avoid absorbing every latest change instantly.


Replies

mmariantoday at 4:52 AM

How would that solve the problem though? You're still bringing compromises in, just with a delay. And the fixes will come in after the compromise, in accordance with the delay policy.

To make matters worse, you'd lose getting alerts on vulnerabilities. Dependabot won't send them, and neither will Renovate last time I checked.