1- trustPolicy : no-downgrade
2-
3- # Wait 7 days (10080 minutes) before installing newly published packages.
4- minimumReleaseAge : 10080
5- minimumReleaseAgeExclude :
6- - ' @anthropic-ai/claude-code@2.1.98'
7- - ' @socketaddon/*'
8- - ' @socketbin/*'
9- - ' @socketregistry/*'
10- - ' @socketsecurity/*'
11-
121packages :
132 - packages/npm/*
143 - perf/*
154 - registry
165 - scripts
176
7+ # Packages allowed to run build scripts (pnpm v11 strictDepBuilds default).
8+ allowBuilds :
9+ esbuild : true
10+
1811catalog :
1912 ' @anthropic-ai/claude-code ' : 2.1.98
2013 ' @babel/core ' : 7.28.4
@@ -34,7 +27,7 @@ catalog:
3427 ' @npmcli/package-json ' : 7.0.0
3528 ' @npmcli/promise-spawn ' : 8.0.3
3629 ' @socketregistry/packageurl-js ' : 1.4.1
37- ' @socketsecurity/lib ' : 5.15 .0
30+ ' @socketsecurity/lib ' : 5.16 .0
3831 ' @types/fs-extra ' : 11.0.4
3932 ' @types/node ' : 24.9.2
4033 ' @types/normalize-package-data ' : 2.4.4
@@ -59,10 +52,10 @@ catalog:
5952 clipboardy : 4.0.0
6053 debug : ^4.4.3
6154 del : 8.0.1
62- ecc-agentshield : 1.4.0
6355 del-cli : 6.0.0
6456 dev-null-cli : 2.0.0
6557 didyoumean2 : 7.0.4
58+ ecc-agentshield : 1.4.0
6659 esbuild : 0.25.11
6760 eslint : 9.35.0
6861 eslint-import-resolver-typescript : 4.4.4
@@ -109,13 +102,14 @@ catalog:
109102 yoctocolors-cjs : 2.1.3
110103 zod : 4.1.12
111104
112- patchedDependencies :
113- brace-expansion@2.0.2 : patches/brace-expansion@2.0.2.patch
114- minimatch@9.0.5 : patches/minimatch@9.0.5.patch
115-
116- # Packages allowed to run build scripts (pnpm v11 strictDepBuilds default).
117- allowBuilds :
118- esbuild : true
105+ # Wait 7 days (10080 minutes) before installing newly published packages.
106+ minimumReleaseAge : 10080
107+ minimumReleaseAgeExclude :
108+ - ' @anthropic-ai/claude-code@2.1.98'
109+ - ' @socketaddon/*'
110+ - ' @socketbin/*'
111+ - ' @socketregistry/*'
112+ - ' @socketsecurity/*'
119113
120114# Dependency overrides (migrated from package.json pnpm.overrides).
121115overrides :
@@ -164,3 +158,8 @@ overrides:
164158 which-boxed-primitive : ' npm:@socketregistry/which-boxed-primitive@1.0.9'
165159 which-collection : ' npm:@socketregistry/which-collection@1.0.8'
166160 which-typed-array : ' npm:@socketregistry/which-typed-array@1.0.9'
161+
162+ patchedDependencies :
163+ brace-expansion@2.0.2 : patches/brace-expansion@2.0.2.patch
164+ minimatch@9.0.5 : patches/minimatch@9.0.5.patch
165+ trustPolicy : no-downgrade
0 commit comments