logoalt Hacker News

dt3fttoday at 3:32 PM2 repliesview on HN

And when you actually need a super hot fix for a 0-day, you will need to revert this and keep it that way for some time to then go back to minimum age.

While this works, we stillneed a permanent solution which requires a sort of vetting process, rather than blindly letting everything through.


Replies

matijstoday at 4:31 PM

pnpm since v10.19.0 allows excluding specific dependencies from minReleaseAge by version.

cortesofttoday at 3:34 PM

Who will do the vetting process?

show 2 replies