Skip to content

Commit 55cf8db

Browse files
committed
fixup! build: enable minimumReleaseAge to mitigate dependency chain attacks
1 parent 44c9d78 commit 55cf8db

File tree

2 files changed

+6
-0
lines changed

2 files changed

+6
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
# The minimum age of a release to be considered for dependency installation.
2+
# The value is in minutes (240 minutes = 4 hours).
3+
minimumReleaseAge: 240

bazel/pnpm-workspace.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,6 @@
1+
# The minimum age of a release to be considered for dependency installation.
2+
# The value is in minutes (240 minutes = 4 hours).
3+
minimumReleaseAge: 240
14
packages:
25
- .
36
- spec-bundling/test/

0 commit comments

Comments
 (0)