Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

TIL: yarn/pnpm has a minimumReleaseAge setting.

"We also suggest you make use of the minimumReleaseAge setting present both in yarn and pnpm. By setting this to a high enough value (like 3 days), you can make sure you won't be hit by these vulnerabilities before researchers, package managers, and library maintainers have the chance to wipe the malicious packages."



This setting is new and was introduced in response to the first round of shai hulud attacks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: