Commit 8501a5a
chore: add .npmrc with supply chain protection (#243)
- save-exact=true: pin exact versions instead of semver ranges
- min-release-age=7: quarantine newly published packages for 7 days
Ref: axios supply chain attack (axios@1.14.1 / plain-crypto-js@4.2.1)
Co-authored-by: Wheeljack <wheeljack@zavi.family>1 parent 83cc673 commit 8501a5a
1 file changed
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
0 commit comments