Skip to content

Conversation

Kocal
Copy link
Member

@Kocal Kocal commented Sep 16, 2025

Q A
Bug fix? no
New feature? no
Docs? no
Issues Fix #...
License MIT

It should not affect us since we are using a lockfile, but just in case of, we prevent the installation of new packages published in the last 1440 minutes (1 day), which could be malicious packages. See https://pnpm.io/fr/settings#minimumreleaseage

@Kocal Kocal self-assigned this Sep 16, 2025
@carsonbot carsonbot added the Status: Needs Review Needs to be reviewed label Sep 16, 2025
@carsonbot carsonbot changed the title Prevent pnpm to install new packages published the same day Prevent pnpm to install new packages published the same day Sep 16, 2025
@Kocal Kocal merged commit e755af1 into symfony:2.x Sep 16, 2025
22 of 24 checks passed
@Kocal Kocal deleted the pnpm-minimumReleaseAge branch September 16, 2025 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Status: Needs Review Needs to be reviewed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants