DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Dependency cooldowns are unfair; we should use phased rollouts instead

Quality: 8/10 Relevance: 9/10

Summary

The article argues that dependency cooldowns are unfair and proposes phased, deterministic rollout windows to reduce supply-chain risk. It outlines how to map project identifiers, package names, versions, and digests to a rollout window, and compares to examples from antivirus, OS/firmware updates, and feature flags. It also discusses tradeoffs and emphasizes that security fixes would still use appropriate rollout policies.

🚀 Service construit par Johan Denoyer