chore: configure 3-day release age gate for npm packages - #10390
chore: configure 3-day release age gate for npm packages#10390dev-hari-prasad wants to merge 1 commit into
Conversation
Set npmMinimalAgeGate to 3d in web/.yarnrc.yml and runtime/.yarnrc.yml to prevent immediately installing freshly-published packages, providing a grace period against npm supply-chain compromises.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 8 included reviews per hour; 6 remain after this review. WalkthroughThe runtime and web Yarn configurations now require npm packages to be at least three days old. Changesnpm package age gate
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to Package resolution in both runtime and web now requires npm releases to be at least three days old, reducing exposure to newly published compromised packages. The change is ready to merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Part of #10363.
Configures Yarn's
npmMinimalAgeGatesetting to3din bothweb/.yarnrc.ymlandruntime/.yarnrc.yml.This introduces a 3-day cooldown period for newly published package versions before they can be resolved, protecting the project against freshly published or compromised npm supply-chain packages while giving the community time to detect and revoke malicious versions.
Changes
npmMinimalAgeGate: 3dtoweb/.yarnrc.ymlnpmMinimalAgeGate: 3dtoruntime/.yarnrc.ymlSummary by CodeRabbit