It doesn't need to, it just updates the code, you have the human publish.
Updates should be changed to delete + publish, and either should require OTP/MFA. You don't need artificial cooldown if you add a manual, informed action in-between. All these publishes went uninformed to their maintainers.. that's the issue.