{"id":26185,"date":"2026-09-21T15:14:09","date_gmt":"2026-09-21T23:14:09","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/ai-coding-agents-a-call-to-action-on-dependency-cooldowns\/"},"modified":"2026-09-21T15:14:09","modified_gmt":"2026-09-21T23:14:09","slug":"ai-coding-agents-a-call-to-action-on-dependency-cooldowns","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/ai-coding-agents-a-call-to-action-on-dependency-cooldowns\/","title":{"rendered":"AI coding agents: A call to action on dependency cooldowns"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>Remember those words of advice for the over-eager from <em>West Side Story<\/em>? \u201cBoy, boy, crazy boy, be cool boy.\u201d They should be heeded by developers hell-bent on installing the latest updates to open-source software. Adopting a \u201ccooldown\u201d policy on updates can be a simple but effective way to avoid downloading malicious code.<\/p>\n<p>Noelle Murata, a senior security engineer at Xcape, said organizations should enforce a three-to-four-day minimum age requirement for new packages and updates.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cA short delay gives the security community time to detect and remove malicious packages, reducing software supply chain risk.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/nmurata\"><span style=\"text-decoration:underline\">Noelle Murata<\/span><\/a><\/p>\n<p>A cooldown of at least one day \u2014 and ideally a week \u2014 keeps you from being first in line, said Waseem Ahmed, head of engineering at Secure.com.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cBy the time the version is eligible to install, the registry, the community, and scanners have usually had time to flag it and pull out.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/waseemahmedk?originalSubdomain=pk\"><span style=\"text-decoration:underline\">Waseem Ahmed<\/span><\/a><\/p>\n<p>Ahmed recommended treating anything freshly published as guilty until proven innocent. \u201cThe pattern over the last year is consistent: When a package gets compromised, the malicious version is usually caught and pulled within hours,\u201d he said. \u201cAxios was flagged in about three hours. The Red Hat packages hit by the Miasma worm were mostly revoked within hours, too.\u201d\u00a0<\/p>\n<p>Here\u2019s why dependency cooldowns are essential in the AI coding age.<\/p>\n<p><strong>[ See webinar:  <\/strong><a href=\"https:\/\/www.reversinglabs.com\/webinar\/your-new-security-playbook-for-ai-driven-software-risk\"><strong>Develop Your New Playbook for AI-Driven Software Risk<\/strong><\/a><strong> ]<\/strong><\/p>\n<h2 id=\"why-cooldowns-are-more-important-now\">Why cooldowns are more important now<\/h2>\n<p>Kennedy Toomey, an application security researcher and advocate at Datadog Security Labs, made the case for dependency cooldowns in a company<a href=\"https:\/\/securitylabs.datadoghq.com\/articles\/dependency-cooldowns\/\"> <span style=\"text-decoration:underline\">blog post<\/span><\/a>. She noted that Axios\u00a0 had over 100 million weekly downloads and that 174,000 other npm packages depend on it. And compromised ecosystems can be particularly impactful.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cSupply chain compromises have not been limited to JavaScript. Attackers have also targeted ecosystems like GitHub Actions and Python.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/kennedy-toomey\"><span style=\"text-decoration:underline\">Kennedy Toomey<\/span><\/a><\/p>\n<p>Datadog&#8217;s 2026 State of DevSecOps report also raised the alarm about early updates.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cOver the past year, we have seen the spread of several large-scale supply chain attacks, most notably s1ngularity and both Shai-Hulud attacks, due in part to organizations using malicious versions of libraries as soon as they\u2019re released. To keep dependencies safe from malware, we recommend pinning dependency versions to a full-length commit SHA.\u201d<\/em><br \/><em>\u2014<\/em>DataDog researchers<\/p>\n<p>However, just because a GitHub Action is pinned to a commit SHA, or hash, doesn\u2019t mean it\u2019s safe, Varun Sharma, co-founder and CEO of StepSecurity, cautioned in a<a href=\"https:\/\/www.linkedin.com\/posts\/varunsharma07_just-because-a-github-action-is-pinned-share-7442593886549716992-MSYK\/\"> <span style=\"text-decoration:underline\">LinkedIn post<\/span><\/a>.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe devil is in the details. Pinning to commit SHAs is a best practice, but you also need to make sure you\u2019re not pinned to a compromised commit SHA.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/varunsharma07\"><span style=\"text-decoration:underline\">Varun Sharma<\/span><\/a><\/p>\n<p>Sharma noted that when Aqua Security\u2019s Trivy ecosystem was compromised in March, there were multiple cases where actions were pinned to commit SHAs, but those SHAs pointed to compromised imposter commits.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cWe have also seen Renovate and Dependabot create [pull requests] to update to the compromised commit SHAs, and those PRs got merged. These workflows continue to exfiltrate secrets on every run, even though they followed the \u2018pin to SHA\u2019 best practice.\u201d<\/em><br \/><em>\u2014<\/em>Varun Sharma<\/p>\n<p>Pinning dependency versions to commit SHAs can be problematic in other ways, warned Vishal Agarwal, CTO of Averlo. \u201cPinning to immutable versions resists supply chain compromise but slows your response when a legitimate vulnerability is disclosed in that dependency,\u201d he said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201c\u2018Patch fast and pin tight\u2019 are in structural conflict. The resolution isn\u2019t a universal rule. It requires understanding which dependencies in your environment create real exploitable risk, what they can reach, and what the consequences of compromise actually are. That context is what determines whether you patch fast, stay pinned, or apply a cooldown.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/vishal-agarwal-55789355\"><span style=\"text-decoration:underline\">Vishal Agarwal<\/span><\/a><\/p>\n<h2 id=\"the-transitive-dependencies-problem\">The transitive dependencies problem<\/h2>\n<p>If pinning dependency versions to a commit SHA isn\u2019t possible, the Datadog report recommends using Yarn or npm, two JavaScript package managers that provide new configurations with a minimum release age to allow time for new versions to be used by others. In addition, GitHub\u2019s Dependabot can add a cooldown time for the same reason. \u201cThis buffer method keeps packages up to date but gives a set time before installation to reduce the likelihood of malicious software. A cooldown of one week could prevent a majority of malicious dependencies from taking root,\u201d the Datadog researchers wrote.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cDependency cooldowns are a sensible first step. In the Axios compromise, malicious versions were live for three hours. A 12-hour cooldown would have blocked most of the damage.\u201d<\/em><br \/><em>\u2014<\/em>Vishal Agarwal<\/p>\n<p>However, cooldowns are not sufficient alone, Agarwal added. \u201cAttackers are already adapting. In the TanStack attack, malicious packages carried valid cryptographic provenance attestations, meaning even organizations verifying package legitimacy got a green light. Patient attackers will delay malicious execution or find other workarounds to survive any cooldown window.\u201d<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cTransitive dependencies compound the problem. The average application now contains over 1,100 open-source components, and 64% of those are transitive dependencies pulled in automatically by your direct dependencies. You never chose them. Most were never reviewed. Cooldowns apply to what you explicitly install, not to the full dependency graph your application actually runs.\u201d<\/em><br \/><em>\u2014<\/em>Vishal Agarwal<\/p>\n<p>John Strand, owner of Black Hills Information Security, said transitive dependencies increase risk because many developers don\u2019t fully understand everything that\u2019s ultimately being included in their applications.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cIt\u2019s very similar to the famous XKCD comic about modern infrastructure resting on a handful of critical open-source projects. The ecosystem is incredibly dynamic and powerful, but every additional dependency expands the potential attack surface.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/john-strand-a1b4b62\"><span style=\"text-decoration:underline\">John Strand<\/span><\/a><\/p>\n<p>Strand argued that cooldowns sound good in theory but aren\u2019t practical in the real world. \u201cModern software development moves too quickly, and organizations are already under pressure to deploy updates and security fixes rapidly. Delaying every new dependency would introduce significant friction into development and could actually create additional security problems,\u201d he said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe theory is that if you wait, someone else will discover the problem first. My concern is that this assumes malicious activity is obvious and immediate. The XZ Utilities incident showed us the opposite. That attacker spent years building trust before introducing malicious code. Nation-state actors are often willing to move slowly and patiently, so simply waiting isn\u2019t a reliable defense.\u201d<\/em><br \/>\u2014John Strand<\/p>\n<p>Strand said dependency cooldowns are flawed because waiting isn\u2019t automatically safer. &#8220;The inverse risk is that a new package or dependency may contain an important security fix that needs to be deployed immediately. Simply waiting and hoping someone else discovers a problem first is not a sustainable security strategy,\u201d he said.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Remember those words of advice for the over-eager fromWest Side Story? \u201cBoy, boy, crazy boy, be cool boy.\u201d They should be heeded by developers hell-bent on installing the latest updates to open-source software. Adopting a \u201ccooldown\u201d policy on updates can be a simple but effective way to avoid downloading malicious code.Noelle Murata, a senior security engineer at Xcape, said organizations should enforce a three-to-four-day minimum age requirement for new packages and updates.\u201cA short delay gives<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26185","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26185","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26185"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26185\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26185"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}