•  
      request #47578 Block "exotic" npm subdeps and prevent trust downgrade during upgrade
    Infos
    #47578
    Thomas Gerbet (tgerbet)
    2026-04-09 11:11
    2026-04-08 17:14
    49305
    Details
    Block "exotic" npm subdeps and prevent trust downgrade during upgrade

    These are 2 recent options of pnpm that can help against certain classes of supply chain compromise.

    https://pnpm.io/supply-chain-security

    Additionaly, dependency updates are now delayed by 12 hours. It can potentially allow the community to detect compromise and pull the packages from the registry. The 12 hours mark should be reasonable with our response time to remediate security advisories and it puts us roughly in the time range it tooks to detect recent large scale supply chain attacks.

    Dev tools
    All
    Empty
    • [ ] enhancement
    • [x] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2026-04-09
    Attachments
    Empty
    References
    Referenced by request #47578

    Follow-ups

    User avatar
    Joris MASSON (jmasson)2026-04-09 11:11
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Connected artifacts