Commit eb596cf
authored
Add pnpm minimumReleaseAge for dependency installation
In light of the recent npm supply chain attacks against
axios, trivy, and surely more to come: never pulling a
dependency until it's at least a day old saves us from
pulling compromised versions before they're discovered
and taken down1 parent 199332a commit eb596cf
1 file changed
Lines changed: 1 addition & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
0 commit comments