Skip to content

feat(ACQ-6387): increase pnpm security settings for @airtasker/proxay#698

Merged
justinnais merged 1 commit intomasterfrom
feat/ACQ-6387-pnpm-security-settings
Mar 3, 2026
Merged

feat(ACQ-6387): increase pnpm security settings for @airtasker/proxay#698
justinnais merged 1 commit intomasterfrom
feat/ACQ-6387-pnpm-security-settings

Conversation

@justinnais
Copy link
Contributor

@justinnais justinnais commented Mar 2, 2026

Summary

Apply supply chain security configuration to pnpm-workspace.yaml per the JavaScript Package Manager Configuration guide.

  • Add strictDepBuilds: true — installation fails if any unlisted package attempts to run a lifecycle script
  • Add blockExoticSubdeps: true — blocks transitive dependencies from non-registry sources
  • Normalise minimumReleaseAgeExclude to inline string format

Closes ACQ-6387

Apply supply chain security configuration per JS Package Manager guide:
- strictDepBuilds: fail if unlisted packages attempt to run scripts
- blockExoticSubdeps: block non-registry dependency sources
- normalise minimumReleaseAgeExclude to inline string format

Note: allowBuilds entries to be populated separately.

Reference: https://airtasker.atlassian.net/wiki/spaces/ENG/pages/4767645728/JavaScript+Package+Manager+Configuration

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@justinnais justinnais self-assigned this Mar 2, 2026
@justinnais justinnais marked this pull request as ready for review March 3, 2026 03:57
@justinnais justinnais requested a review from a team as a code owner March 3, 2026 03:57
@justinnais justinnais requested a review from peaonunes March 3, 2026 03:57
@justinnais justinnais enabled auto-merge (squash) March 3, 2026 03:58
@justinnais justinnais merged commit 27080b6 into master Mar 3, 2026
9 checks passed
@justinnais justinnais deleted the feat/ACQ-6387-pnpm-security-settings branch March 3, 2026 03:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants