Loading…
Tuesday October 6, 2026 14:37 - 14:55 CEST
Setting a minimum release age is a new feature of npm, pnpm, Yarn, and other package managers, introduced to provide a mechanism for mitigating the impact of malware being uploaded to npm. However, no evidence-based analysis has been performed to determine how this security mechanism should be tuned to make effective use of it. To close this gap, we analyze the GitHub Advisory Database to collect data on the timeline of malware detection. Building upon prior work on measuring malicious package detection and popularity-weighted impact, we combine historical malicious package detection and npm download metrics to estimate minimum release age thresholds that can provide developers with confidence that updated releases contain no malicious code. To our knowledge, we are the first to provide evidence based recommendations for setting the recently introduced minimum release age feature. By conducting this study, we hope to provide real world benefits to developer security. Based on our study of malware detection time using the GitHub Advisory Database, we find that a general recommendation of setting the minimum release age to 8 days provides significant security benefits with little to no negative impact on developers.
Speakers
DT

Dominic Tassio

PhD Student, University of Kansas
Dominic is a PhD student in Computer Science at the University of Kansas's Institute for Information Sciences. His research explores programming language ecosystems and software supply-chain security, particularly within npm. He previously presented at SCORED '25 on the usage of HTTP(S... Read More →
Tuesday October 6, 2026 14:37 - 14:55 CEST
South Hall 3A

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link