Skip to content

security: add minimum release age (7 days) - #56

Open
wera-trollcode wants to merge 1 commit into
masterfrom
security/min-release-age
Open

security: add minimum release age (7 days)#56
wera-trollcode wants to merge 1 commit into
masterfrom
security/min-release-age

Conversation

@wera-trollcode

@wera-trollcode wera-trollcode commented Jun 10, 2026

Copy link
Copy Markdown

Introduces a 7-day minimum release age gate to mitigate npm supply-chain attacks (preventing the installation of brand-new, potentially malicious packages).

As part of the initiative described here, I am leaving this PR open for the repository maintainers to review, discuss, and decide on adoption.

@andrzejkupczyk
andrzejkupczyk requested a balanced review from Copilot August 31, 2026 12:09

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The configured value represents 2 hours 48 minutes, not the intended 7 days.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds an npm dependency-age gate to reduce supply-chain risk.

Changes:

  • Configures a minimum package release age in .npmrc.
File summaries
File Description
.npmrc Adds the release-age restriction.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .npmrc
@@ -0,0 +1 @@
min-release-age=10080
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants