npm CLI 11.10.0 introduces three notable security and workflow improvements. The new `minimumReleaseAge` setting lets teams enforce a cooldown before newly published package versions can be installed, reducing exposure to malicious packages before detection. A new `--allow-git` flag closes a code execution path via Git
•4m read time• From socket.dev
Table of contents
New minimumReleaseAge Setting #Closing a Git Execution Path During Install #Bulk OIDC Configuration for Trusted Publishing #Ecosystem Alignment on Supply Chain Controls #Sort: