pnpm 10.16 Adds New Setting for Delayed Dependency Updates -...
Blog post from Socket
In response to a series of supply chain attacks on npm packages, pnpm version 10.16 has introduced a new setting called `minimumReleaseAge`, which enforces a delay before newly published packages can be installed, aiming to protect against zero-hour vulnerabilities while maintaining build stability. This setting specifies a mandatory waiting period, allowing tools like Taze and npm-check-updates to adopt similar features, reflecting a shift towards prioritizing security over immediate package updates in the JavaScript community. The approach involves fetching full package metadata, which may slow down installations but improves caching, and includes features to bypass the delay for trusted or internal packages. While the delay is seen as a buffer against opportunistic attacks, some critics argue it may be inadequate against sophisticated threats, highlighting the need for a balance between security measures and workflow simplicity. Despite the skepticism, these features are increasingly seen as a necessary layer of defense, helping to reduce the risk of malware during the critical initial release period, though not a substitute for comprehensive security practices.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.