Package agnostic security:minimumReleaseAge preset #40553
Replies: 2 comments 2 replies
-
|
I think, yes it would be useful to have Although we don't have any Issues to track it, this is something we are definitely interested in doing The reason we've not yet worked on this is two part - time and time 🤓 Kidding aside, there's a fair bit of work we'd put into enablement of the feature for the npm datasource - a lot of that is done now (either general hardening of the feature, or working out how best to work with the managers), but we'd still want to make sure that we'd considered some similar cases for different datasources/managers i.e. To be extra clear to anyone reading - this isn't an "on by default" preset we're talking about, but a handy way of turning this on for a specific datasource We could use a templated preset to parameterise the "number of days" to wait, if that would be useful |
Beta Was this translation helpful? Give feedback.
-
|
Which Managers/Datasources would you be thinking of this being for? Are you currently using |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Tell us more.
There is currently the security:minimumReleaseAgeNpm that is specific to NPM. With the support for release age for other registries, it would be useful to provide a single preset to set a release for all package managers. I would like to better understand if the other registries would benefit from having similar exceptions like the NPM preset. Do anyone know?
Beta Was this translation helpful? Give feedback.
All reactions