Skip to content

ci: exclude packages newer than 7 days in lockfile update workflow#2130

Open
lkstrp wants to merge 2 commits intoPyPSA:masterfrom
lkstrp:update-delay
Open

ci: exclude packages newer than 7 days in lockfile update workflow#2130
lkstrp wants to merge 2 commits intoPyPSA:masterfrom
lkstrp:update-delay

Conversation

@lkstrp
Copy link
Copy Markdown
Member

@lkstrp lkstrp commented Mar 27, 2026

Exclude recently published packages to avoid pulling in broken or yanked releases before upstream had time to react. This reduces exposure to supply chain attacks, like the recent litellm one, which was only online for a couple of hours, before getting yanked.

@lkstrp lkstrp requested a review from brynpickering March 27, 2026 09:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant