-
Notifications
You must be signed in to change notification settings - Fork 4.2k
Open
Labels
Bugthing that needs fixingthing that needs fixingNeeds Triageneeds review for next stepsneeds review for next steps
Description
Is there an existing issue for this?
- I have searched the existing issues
This issue exists in the latest npm version
- I am using the latest npm
Current Behavior
In light of the recent cline2.3 injection attack I would like to propose that the default of "min-release-age" be set to seven days.
(see: GHSA-9ppg-jx86-fqw7
and: https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another )
Per https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns the majority of compromised/malicious NPM packages are detected and remediated within hours or a small number of days.
While anyone can set that number to whatever they want, I believe that defaulting min-release-age to a generous safety margin would effectively mitigate a great deal of ecosystem risk at negligible cost.
Expected Behavior
No response
Steps To Reproduce
No response
Environment
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Bugthing that needs fixingthing that needs fixingNeeds Triageneeds review for next stepsneeds review for next steps