I agree, but in most recent cases a 1 day cooldown would have been enough.

I added a “how to bypass if you have to patch a zero day CVE” section to depsguard for all supported package managers.