@mhoye Do you have links to these issues? I have been thinking along similar lines, so would like to hear arguments against.
@mhoye I've found the issues for uv and pip, I'll be reading through these. Thanks for starting these discussions a few weeks ago.
Proposal: set exclude-newer default to seven days. · Issue #18326 · astral-sh/uv

Summary In light of the recent cline2.3 injection attack I would like to propose that a default value of "exclude-newer", if left unspecified, be set to seven days. (see here and here. Per this art...

GitHub