A dependency cooldown is a deliberate delay (e.g., three days) before adopting new package versions. This practice protects against supply chain attacks by ensuring you install older, vetted versions rather than immediately adopting potentially compromised new releases. In the Axios case, a three-day cooldown would have meant installing a pre-breach version during the two-hour attack window.