Skip to content

Upgrade pnpm supply-chain safeguards#618

Merged
JoviDeCroock merged 1 commit into
mainfrom
chore/pnpm-11-supply-chain-window
May 12, 2026
Merged

Upgrade pnpm supply-chain safeguards#618
JoviDeCroock merged 1 commit into
mainfrom
chore/pnpm-11-supply-chain-window

Conversation

@JoviDeCroock
Copy link
Copy Markdown
Member

Summary

  • upgrade pinned pnpm usage to pnpm 11
  • configure a 7-day minimumReleaseAge window for installs
  • explicitly block exotic transitive dependencies

Why

Upgraded every repo to pnpm 11, so we inherit the ecosystem install-cooldown behaviour. It's not a fix on its own. It buys us a window.

Testing

  • Not run; config-only change.

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented May 12, 2026

⚠️ No Changeset found

Latest commit: 35a00dd

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@JoviDeCroock JoviDeCroock force-pushed the chore/pnpm-11-supply-chain-window branch 2 times, most recently from 9ae643e to ed45723 Compare May 12, 2026 17:44
@JoviDeCroock JoviDeCroock force-pushed the chore/pnpm-11-supply-chain-window branch from ed45723 to 35a00dd Compare May 12, 2026 17:47
@JoviDeCroock JoviDeCroock merged commit e10c13b into main May 12, 2026
1 check passed
@JoviDeCroock JoviDeCroock deleted the chore/pnpm-11-supply-chain-window branch May 12, 2026 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant