Skip to content

chore: add minimum release age to .npmrc#28

Merged
jdalton merged 1 commit intomainfrom
chore/min-release-age
Apr 2, 2026
Merged

chore: add minimum release age to .npmrc#28
jdalton merged 1 commit intomainfrom
chore/min-release-age

Conversation

@jdalton
Copy link
Copy Markdown
Collaborator

@jdalton jdalton commented Apr 2, 2026

Summary

  • Add minimum-release-age=10080 (pnpm, minutes) and min-release-age=7 (npm v11+, days) to .npmrc
  • Enforces a 7-day waiting period before installing newly published packages, reducing supply chain attack risk
  • pnpm reads minimum-release-age from .npmrc; npm v11+ reads min-release-age; each ignores the other's key

Test plan

  • CI passes

Add minimum-release-age=10080 (pnpm, minutes) and min-release-age=7
(npm v11+, days) to enforce a 7-day waiting period before installing
newly published packages, reducing supply chain attack risk.
@jdalton jdalton merged commit eb3b024 into main Apr 2, 2026
9 checks passed
@jdalton jdalton deleted the chore/min-release-age branch April 2, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant