Repository navigation
Expand file tree
/
Copy pathpnpm-workspace.yaml
More file actions
43 lines (37 loc) · 1.68 KB
/
Copy pathpnpm-workspace.yaml
File metadata and controls
43 lines (37 loc) · 1.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
# Supply chain security defaults. https://pnpm.io/supply-chain-security
# pnpm v11+ enables most of these by default; they are pinned explicitly so an
# accidental version downgrade or config drift does not silently weaken posture.
# Wait 7d after publish before resolving a new version. Buys time for malicious
# releases (typosquats, hijacked maintainer accounts) to be yanked.
minimumReleaseAge: 4320 # 3 days
# Bypass the cooldown for packages we trust to ship clean hotfixes quickly.
# Accepts bare names, name@version, disjunctions (`a || b`), and globs (`@scope/*`).
minimumReleaseAgeExclude:
- next
# Reject transitive deps that resolve to git/tarball URLs. Only direct deps may
# use exotic sources.
blockExoticSubdeps: true
# Fail install if a dep has a lifecycle script that is not explicitly allowed
# below, instead of silently skipping it.
strictDepBuilds: true
# Explicit allowlist of packages permitted to run install/postinstall scripts.
# Everything else is blocked. Audit any addition here.
allowBuilds:
'@sentry/cli': true
'@swc/core': true
esbuild: true
husky: true
sharp: true
unrs-resolver: true
core-js: false
core-js-pure: false
msw: false
overrides:
vite: '^8.0.0'
# Security patches for transitive deps flagged by `pnpm audit` whose parents
# have not yet released a bump. Remove an entry once the parent pulls it in.
'brace-expansion@5': '>=5.0.8' # via @sentry/nextjs (build). Only the 5.x copy.
fast-uri: '^3.1.4' # via @hookform/resolvers>ajv. Stay on 3.x for ajv compat.
postcss: '^8.5.18' # via next / @mdx-js/loader>webpack.
sharp: '^0.35.0' # via next image optimization (runtime).
valibot: '^1.4.2' # via @hookform/resolvers (unused resolver).