fix: pnpm の minimumReleaseAge を有効にする - #304
Merged
Merged
Conversation
公開直後のバージョンを install しない cooldown を有効にする。npm の サプライチェーン攻撃では、汚染されたバージョンが公開されてから削除される までの時間が短いことが多いため、一定期間経過した版だけを使うことで その窓を避けられる。 設定は pnpm-workspace.yaml のトップレベルに書く必要がある。`pnpm:` キーの 下にネストすると pnpm が警告もエラーも出さずに無視する。 検証(pnpm 10.32.1、manage-package-manager-versions=false): - `pnpm config get minimumReleaseAge` → 10080 - `pnpm install --lockfile-only --ignore-scripts` → pnpm-lock.yaml に差分なし https://pnpm.io/settings/dependency-resolution#minimumreleaseage Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
sksat (sksat)
force-pushed
the
fix/enable-minimum-release-age
branch
from
August 4, 2026 15:23
c3c5255 to
020d0ab
Compare
Shu Kutsuzawa (cappyzawa)
approved these changes
Aug 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
client-uiに pnpm のminimumReleaseAgeを 7 日(10080 分)で設定します。公開直後のバージョンを install しないことで、汚染された版が公開されてから削除されるまでの窓を避けられます。検証(pnpm 10.32.1):
pnpm config get minimumReleaseAge→10080/pnpm install --lockfile-only --ignore-scriptsでpnpm-lock.yamlに差分なし。公開直後の版を入れたいときは
pnpm add <pkg> --config.minimumReleaseAge=0、恒久的な例外はminimumReleaseAgeExcludeを使ってください。