Commit 60c9040
chore: add pnpm minimumReleaseAge supply-chain delay (#154)
Set minimumReleaseAge to 2880 minutes (48h) so newly published dependency
versions must age before install, mitigating supply-chain attacks. Exclude
our own '@humanspeak/*' scope so first-party releases are not delayed.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent b611c53 commit 60c9040
1 file changed
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
0 commit comments