Skip to content

chore: increase pnpm minimumReleaseAge to 7 days#1897

Open
devin-ai-integration[bot] wants to merge 2 commits into
mainfrom
devin/1778598774-increase-minimum-release-age
Open

chore: increase pnpm minimumReleaseAge to 7 days#1897
devin-ai-integration[bot] wants to merge 2 commits into
mainfrom
devin/1778598774-increase-minimum-release-age

Conversation

@devin-ai-integration
Copy link
Copy Markdown
Contributor

@devin-ai-integration devin-ai-integration Bot commented May 12, 2026

Summary

Increases pnpm's minimumReleaseAge from the default 1 day (1440 minutes) to 7 days (10080 minutes) for improved supply-chain protection.

Screenshots (if appropriate):

N/A

Testing approaches

Config-only change — CI validates the workspace config is well-formed.

Link to Devin session: https://app.devin.ai/sessions/80e39d96e12e4e60ba87aae700bb1094


Note

Low Risk
Low risk config change that only affects dependency resolution by requiring packages to be at least 7 days old, which could delay adoption of newly published versions.

Overview
Increases pnpm’s minimumReleaseAge to 10080 minutes (7 days), so dependency resolution prefers versions that have been published for at least a week as a supply-chain hardening measure.

Reviewed by Cursor Bugbot for commit ff08d8b. Bugbot is set up for automated code reviews on this repo. Configure here.

Co-Authored-By: alexis@launchdarkly.com <alexis@launchdarkly.com>
@devin-ai-integration
Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented May 12, 2026

⚠️ No Changeset found

Latest commit: ff08d8b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Co-Authored-By: alexis@launchdarkly.com <alexis@launchdarkly.com>
@apucacao apucacao marked this pull request as ready for review May 12, 2026 15:30
@apucacao apucacao requested a review from a team as a code owner May 12, 2026 15:30
@apucacao apucacao requested a review from pkaeding May 12, 2026 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants