Security protections
Cooling off new releases
Hold brand new versions for a few days, when most malicious releases are caught.
Most malicious releases are found and pulled within days. Cooling off, in hours (Settings, Policy, default 0 which is off) hides versions younger than that from metadata and refuses them by URL. Developers get "published 3 hours ago, new versions wait 72 hours (served from ...)".
- Never cooled off: name patterns that skip the wait, like
@acme/*. - A version with no publish time:
allow(default) orhold. - An allow rule that pins the exact version skips the wait, and so does a cooling off waiver.
- Audit mode turns cooling off off.
Tip
72 hours is a common choice. Pair it with a cooling off waiver process for urgent security fixes.