Provides a 'Window of Detection' analysis for supply chain attacks and identifies a 7-14 day 'Cooldown' period as a high-confidence mitigation strategy for automated dependency updates.
Dependency cooldowns—a deliberate waiting period before adopting a new package release—are identified as a highly effective mitigation for the majority of open-source supply chain attacks. Analysis of prominent incidents (e.g., xz-utils, Ultralytics, web3.js) reveals that while attack staging can take weeks, the 'window of opportunity' between malicious upload and detection/removal is typically between 1 hour and 10 days. Remarkably, 80% of these attacks had detection windows of less than a week. A 7-day cooldown would have prevented the vast majority of these compromises from reaching end users, while a 14-day window would have stopped all but the most advanced outlier (xz-utils, which had a 5-week window). Cooldowns are easily implementable via tools like Dependabot or Renovate, or directly through package managers like pnpm using the `minimumReleaseAge` setting.
The report argues that 'staying up to date' too quickly is a risk factor, and that waiting out a 7-14 day window allows the security community to detect and remove malicious versions.
consuming a compromised, malicious release during the critical first week of its public existence
while staleness is a risk for unpatched bugs, 'freshness' is a documented risk factor for supply chain compromise, validating the use of a 'maturity age' for dependency adoption.
Attackers move into the public with malicious changes that have a very limited window of opportunity (often hours or days) before detection by scanning vendors.
exposure to high-impact, low-dwell-time attacks from compromised or ephemeral repositories
the rapid detection and removal of malware by indices means that new code is the primary staging window for high-risk supply chain exploits.
8/10 attacks had windows of opportunity of less than a week... a cooldown of 7 days would have prevented the vast majority... all but 1 [xz-utils].
Risk Guard encourages using the latest version but does not flag 'Newness' as a risk factor or suggest a 'Cooldown' period for newly published releases.
Risk Guard would be better if it implemented a 'Minimum Maturity Age' check that flagged dependencies published in the last 7-14 days as high-risk for potential undiscovered compromise.