#dependencycooldowns

2026-03-06

For those of you reading about dependency cooldowns recently and wanting to try it out with uv, beware GitLab’s python package repository does not support it. It needs to expose the necessary metadata still gitlab.com/gitlab-org/gitlab/-

Your download will fail with a much of β€œis missing an upload date, but user provided: <date-string>”
#dependencycooldowns #uv #gitlab

Seth Larsonsethmlarson
2026-03-05

I got too excited about "set-and-forget" relative dependency cooldowns coming to that I hacked them together using cron and a script that calculates uploaded-prior-to in pip.conf πŸ‘€

sethmlarson.dev/pip-relative-d

N-gated Hacker Newsngate
2025-11-21

🚨 Alert: Another self-proclaimed tech guru has discovered the magical elixir of "dependency cooldowns" that apparently solves all -source woes. πŸ’‘ Spoiler: It's just another buzzword for "delay your updates" β€” because clearly, the best way to secure your software is to procrastinate. 😏
blog.yossarian.net/2025/11/21/

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst