Skip to content

feat: warn when min-release-age blocks an audit fix#9544

Open
JamieMagee wants to merge 2 commits into
npm:latestfrom
JamieMagee:audit-fix-release-age-warning
Open

feat: warn when min-release-age blocks an audit fix#9544
JamieMagee wants to merge 2 commits into
npm:latestfrom
JamieMagee:audit-fix-release-age-warning

Conversation

@JamieMagee

Copy link
Copy Markdown
Contributor

npm audit fix left a package on its vulnerable version, with no warning, when the only patched version was newer than the min-release-age/before cutoff. It now warns which fix was blocked and exits non-zero. Honors min-release-age-exclude.

@JamieMagee JamieMagee requested review from a team as code owners June 12, 2026 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant