Skip to content

Avoid installing newly released versions of our dependencies #9162

@GytisCepk

Description

@GytisCepk

With increased number of compromised packages recently, we should consider adding minimumReleaseAge to our common/config/rush/.npmrc. Recommended value would probably be 1440 (one day).

Prerequisites:

  • Update pnpm version to 10.16.0

Metadata

Metadata

Assignees

Labels

buildologyIssues related to process, tooling or CI/CD pipelinessecurity

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions