Skip to content

Add minReleaseAge to pnpm settings to reduce likelihood of supply chain compromises#5798

Merged
rtibbles merged 2 commits intolearningequality:unstablefrom
bjester:min-release-age
Apr 1, 2026
Merged

Add minReleaseAge to pnpm settings to reduce likelihood of supply chain compromises#5798
rtibbles merged 2 commits intolearningequality:unstablefrom
bjester:min-release-age

Conversation

@bjester
Copy link
Copy Markdown
Member

@bjester bjester commented Mar 31, 2026

Summary

  • Using minimumReleaseAge should reduce likelihood of supply chain compromises
  • Sets the minimumReleaseAge to 1 week to match dependabot
  • Upgrades pnpm since the feature needs at least 10.16.0

References

https://nesbitt.io/2026/03/04/package-managers-need-to-cool-down.html

Reviewer guidance

Can you run pnpm install?

@bjester bjester requested a review from marcellamaki March 31, 2026 15:06
@rtibbles rtibbles merged commit 85dcbc2 into learningequality:unstable Apr 1, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants