-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathbunfig.toml
More file actions
15 lines (15 loc) · 779 Bytes
/
Copy pathbunfig.toml
File metadata and controls
15 lines (15 loc) · 779 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
[install]
# Supply-chain hardening: refuse npm packages whose latest matching version
# was published less than 3 days (259200 s) ago, so a freshly compromised
# release has a quarantine window before it can land in this project.
#
# Mechanism: Bun translates this into a `before = now − minimumReleaseAge`
# date filter at resolution time. The lockfile is unaffected; existing
# pinned versions install regardless. The gate only fires when resolving
# a new version (`bun add`, `bun update`, an unlocked install).
#
# To exempt a trusted package from the age gate, add it to
# `minimumReleaseAgeExcludes` below. Keep the exclude list minimal —
# every entry is an explicit "we trust this maintainer to ship safely".
minimumReleaseAge = 259200
minimumReleaseAgeExcludes = []