From 9407ac87df0385f0e3aa845e01cfbb49f249814e Mon Sep 17 00:00:00 2001 From: Altay Date: Tue, 31 Mar 2026 16:26:39 +0300 Subject: [PATCH] build: move pnpm minimum release age to workspace config --- package.json | 4 ---- pnpm-workspace.yaml | 7 +++++++ 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/package.json b/package.json index e2e0d11ccfa..d5e9746bfcf 100644 --- a/package.json +++ b/package.json @@ -1249,10 +1249,6 @@ }, "packageManager": "pnpm@10.32.1", "pnpm": { - "minimumReleaseAge": 2880, - "minimumReleaseAgeExclude": [ - "@mariozechner/*" - ], "overrides": { "hono": "4.12.9", "@hono/node-server": "1.19.10", diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index e076fb0a4c4..f7182e1ccf2 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -4,6 +4,13 @@ packages: - packages/* - extensions/* +# Delay new releases by 48h to reduce exposure to compromised packages, +# while allowing our explicitly trusted Pi packages to update immediately. +minimumReleaseAge: 2880 + +minimumReleaseAgeExclude: + - "@mariozechner/*" + onlyBuiltDependencies: - "@lydell/node-pty" - "@matrix-org/matrix-sdk-crypto-nodejs"