-
Notifications
You must be signed in to change notification settings - Fork 650
Closed
Labels
effort: easyProbably a quick fix. Want to contribute? :-)Probably a quick fix. Want to contribute? :-)help wantedIf you're looking to contribute, this issue is a good place to start!If you're looking to contribute, this issue is a good place to start!
Description
Summary
I'd like to request adding support for pnpm's new minimumReleaseAge setting.
Details
There have been at least two high profile supply chain attacks on npm recently and this setting is designed to mitigate these attacks by requiring a minimum age on the installed versions. Most attacks are discovered and removed within 24 hours and having access to this setting will help prevent supply chain attacks in my project and others.
Standard questions
Please answer these questions to help us investigate your issue more quickly:
Question | Answer |
---|---|
@microsoft/rush globally installed version? |
5.149.1 |
rushVersion from rush.json? |
5.149.1 |
useWorkspaces from rush.json? |
true |
Operating system? | Linux |
Would you consider contributing a PR? | Yes |
Node.js version (node -v )? |
22.14.0 |
keemor, wtuminski, gregbalnis and yurii20041
Metadata
Metadata
Assignees
Labels
effort: easyProbably a quick fix. Want to contribute? :-)Probably a quick fix. Want to contribute? :-)help wantedIf you're looking to contribute, this issue is a good place to start!If you're looking to contribute, this issue is a good place to start!
Type
Projects
Status
Closed