Skip to content

Commit e5058dc

Browse files
authored
chore(security): enable the npm supply-chain cooldown on npm 11 (#608)
* chore(security): enable the npm supply-chain cooldown on npm 11 Sets `min-release-age=2` and `min-release-age-exclude[]=@conduction/*`, raises `engines.npm` to ^11.0.0, and regenerates the lockfile under npm 11. The .npmrc comment here has described a cooldown for months and it has never been in effect. `min-release-age` does not exist in npm 10 — `npm config get min-release-age` answers `undefined` — and every Node 22 release bundles npm 10, so the setting was read by nothing. Most repos also had it at 0, which disables it outright. @conduction/* is exempt because without the exemption the cooldown does not fail loudly, it silently resolves backwards: measured 2026-08-15, an install of @conduction/nextcloud-vue on release day picked 2.0.7 instead of 2.3.0 and exited 0. The lock is regenerated under npm 11 and iterated to a fixed point. Where the tree changed rather than its metadata, that is npm 10 -> 11 reconciling a lock shaped by the older resolver, not the cooldown — verified by regenerating with the cooldown enabled and disabled and getting identical trees. Verified: npm ci exit 0 under npm 11.19.0, @conduction/nextcloud-vue resolves to 2.3.0, gate-84 conformance passes. * ci: re-run against the merged shared workflow `gh run rerun` replays the workflow version resolved when the run was created, so a reusable workflow referenced as @main is NOT re-resolved — every re-run after ConductionNL/.github#469 merged still executed Node 22 with npm 10.9.8, where `min-release-age` does not exist and `npm ci` cannot read an npm-11 lockfile. Only a new run picks up the merged workflow. This empty commit is that trigger.
1 parent f5b6c39 commit e5058dc

3 files changed

Lines changed: 32 additions & 103 deletions

File tree

‎.npmrc‎

Lines changed: 17 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,17 @@
1-
# Supply-chain hardening: reject any npm package published less than
2-
# 24h ago. Compromised first-party-Conduction packages are excluded via
3-
# Dependabot cooldown (.github/dependabot.yml); for fresh @conduction/*
4-
# releases, override per-install with `npm install --min-release-age=0`.
5-
min-release-age=0
1+
# Supply-chain hardening: npm will not install a version published less than
2+
# 2 days ago, so a compromised release has a window in which it can be pulled
3+
# before it reaches this repo.
4+
#
5+
# npm 11+ ONLY. On npm 10 `min-release-age` does not exist — `npm config get
6+
# min-release-age` answers `undefined` — so this file is INERT on that
7+
# toolchain and the guard is not in effect. `engines.npm` declares the floor
8+
# and CI runs Node 24, which bundles npm 11; every Node 22 release bundles
9+
# npm 10 and cannot enforce this. gate-84 checks the three move together.
10+
#
11+
# @conduction/* is exempt so our own same-day releases still resolve. Without
12+
# the exemption the cooldown does NOT fail loudly — it silently resolves
13+
# backwards: measured 2026-08-15, installing @conduction/nextcloud-vue on
14+
# release day picked 2.0.7 instead of 2.3.0 and exited 0. Only the named
15+
# packages are exempt; their own dependencies still follow the policy.
16+
min-release-age=2
17+
min-release-age-exclude[]=@conduction/*

0 commit comments

Comments
 (0)