Haha what if there's an urgent security fix in an updated package?

Manually review the package and override the setting

The flaw of the cooldown solution speaks for itself.

Still it's something like a second factor (or even, literally, overriding might require 2FA).

[deleted]

Yep, that's the main argument against cooldowns, but there are ways to override them. I'll update the docs soon.