Skip to content

[rush] Support pnpm's minimumReleaseAge setting #5372

@briancmpbll

Description

@briancmpbll

Summary

I'd like to request adding support for pnpm's new minimumReleaseAge setting.

Details

There have been at least two high profile supply chain attacks on npm recently and this setting is designed to mitigate these attacks by requiring a minimum age on the installed versions. Most attacks are discovered and removed within 24 hours and having access to this setting will help prevent supply chain attacks in my project and others.

Standard questions

Please answer these questions to help us investigate your issue more quickly:

Question Answer
@microsoft/rush globally installed version? 5.149.1
rushVersion from rush.json? 5.149.1
useWorkspaces from rush.json? true
Operating system? Linux
Would you consider contributing a PR? Yes
Node.js version (node -v)? 22.14.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort: easyProbably a quick fix. Want to contribute? :-)help wantedIf you're looking to contribute, this issue is a good place to start!

    Type

    No type

    Projects

    Status

    Closed

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions