Skip to content

chore(security): add min-release-age=3 to .npmrc#152

Open
ms-bot wants to merge 1 commit into
masterfrom
mobsuccessbot/npmrc-min-release-age
Open

chore(security): add min-release-age=3 to .npmrc#152
ms-bot wants to merge 1 commit into
masterfrom
mobsuccessbot/npmrc-min-release-age

Conversation

@ms-bot
Copy link
Copy Markdown
Contributor

@ms-bot ms-bot commented May 21, 2026

Why is this needed?

This pull request has been created by a robot to add supply chain protection.

Adding min-release-age=3 to .npmrc prevents npm from installing packages published less than 3 days ago, protecting against attacks like the TanStack compromise (May 2026).

Requires npm ≥ 11.10 — already enforced by the generated npm.yml workflow.

@ms-bot ms-bot added the mobsuccessbot Pull requests that enforce company policies label May 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

mobsuccessbot Pull requests that enforce company policies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant