Earlier quoted context omitted.
I also was at this point, and I decided to add cooldowns to every project.
Yeah, I agree, but then you are at the mercy of whatever vulnerability is found in the current version(s). It just feels like a lose-lose situation no matter what you do.
pnpm audit —fix for example will whitelist releases in cooldown phase when theres a known security issue for a version you currently use.