logoalt Hacker News

datakanyesterday at 3:25 PM3 repliesview on HN

I don't think so at all. People go on vacation all the time. This should be 30 days not 3.


Replies

Waterluvianyesterday at 3:31 PM

That's the usual runaway problem, right? Why not 60 then? People go on sabbaticals! etc etc.

I feel like the only way to be wrong for this class of problem is to believe that there's a singular right answer. Just pick something reasonable (like how weekends are a fairly common thing, so don't make it shorter than 48 hours). Start there, then see how much of an issue persists. No matter what, at scale you'll find someone complaining that the number is too little, and people complaining that it's too much. Eventually you just have to tell the complainers to deal with it.

show 1 reply
Normal_gaussianyesterday at 5:01 PM

It sounds like we should plot 'count of compromised repos' against 'time taken for maintainer to initiate a resolution', and pick something just after the inflection point.

normie3000yesterday at 3:39 PM

It's often not the maintainer that removes a poisoned release, it's the npm security team/tools. So unless the whole team takes a month off, we're all safe.