Skip to content

Commit f40cd67

Browse files
authored
chore: add minimum release age to .npmrc (#1152)
* chore: add agent protocol sections to CLAUDE.md * chore: add minimum release age to .npmrc Add minimum-release-age=10080 (pnpm, minutes) and min-release-age=7 (npm v11+, days) to enforce a 7-day waiting period before installing newly published packages, reducing supply chain attack risk.
1 parent 0a9e4b8 commit f40cd67

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

.npmrc

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,11 @@ link-workspace-packages=false
66
loglevel=error
77
prefer-workspace-packages=false
88

9+
# Minimum release age - wait 7 days before installing newly published packages
10+
# pnpm uses minimum-release-age (minutes), npm v11+ uses min-release-age (days)
11+
minimum-release-age=10080
12+
min-release-age=7
13+
914
# Trust policy - prevent downgrade attacks
1015
trust-policy=no-downgrade
1116
trust-policy-exclude[]=undici@6.21.3

0 commit comments

Comments
 (0)