-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathpnpm-workspace.yaml
More file actions
23 lines (22 loc) · 1 KB
/
Copy pathpnpm-workspace.yaml
File metadata and controls
23 lines (22 loc) · 1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
onlyBuiltDependencies:
- '@vercel/speed-insights'
- sharp
- unrs-resolver
# Supply-chain cooldown: refuse to resolve any version published less than
# 7 days ago, so a compromised release has time to be caught and unpublished.
#
# The unit is MINUTES, not seconds (pnpm computes
# `Date.now() - minimumReleaseAge * 60 * 1000`), so 10080 = 7 days. A value
# that looks like a seconds-based fortnight (1209600) is really ~840 days and
# blocks essentially every package on npm.
#
# This is pinned here on purpose. pnpm itself ships no default, so without
# this line the value is inherited from whatever each contributor happens to
# have in their global pnpm rc — which is how the ~840-day lockout got in.
#
# To install something newer than the window (an urgent security patch):
# pnpm add <pkg> --config.minimumReleaseAge=0
# For a package that needs a standing exemption, add a
# `minimumReleaseAgeExclude` list here. CI is unaffected: `--frozen-lockfile`
# skips resolution entirely.
minimumReleaseAge: 10080