Commit 7e4a8b6
committed
dev: add minimum dependency age of 72h against supply chain attacks
Reduce the risk of installing malicious packages when upgrading dependency versions
by only allowing package versions published at least 72h ago.
As most malicious packages are discovered and blocked within this time,
this reduces the risk of accidentally installing them.1 parent 2d4eee9 commit 7e4a8b6
1 file changed
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
0 commit comments