Package age filtering for proxy mode #5386
Replies: 2 comments 1 reply
-
|
Pnpm released something similar you suggest https://github.com/pnpm/pnpm/blob/HEAD/pnpm/CHANGELOG.md#10160 Not saying bad idea but worth debate side effects, challenges, etc... |
Beta Was this translation helpful? Give feedback.
-
|
Hi. I just released filter plugin that allows you to delay package availability with Verdaccio. You can install it as npm package and configure how long you want new package versions to be delayed. Note that it works in recently released Verdaccio 6.2.0. If you're on previous version, plugin won't be loaded. More instructions here: https://www.npmjs.com/package/verdaccio-plugin-delay-filter |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Given raising number of supply chain attacks against public npm registries, it would be great to be able to delay package availability in proxy mode until N hours (configurable) . Idea is to prevent access to those packages until they live for a while in public space and (hopefully) by the time the quarantine threshold passes the malicious activities are already discovered.
There should be some kind of override config as well (in case we want to allow critical security patches sooner) . That would be manual action though.
Beta Was this translation helpful? Give feedback.
All reactions