Skip to content

Commit f46655f

Browse files
authored
Merge pull request #109 from d-zero-dev/fix/supply-chain-security
fix(repo): add supply chain attack mitigations
2 parents 71ddb6f + 0dae91d commit f46655f

3 files changed

Lines changed: 10 additions & 1 deletion

File tree

.github/renovate.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,12 @@
1212
"enabled": true,
1313
"automerge": true
1414
},
15+
"minimumReleaseAge": "7 days",
16+
"internalChecksFilter": "strict",
17+
"osvVulnerabilityAlerts": true,
18+
"vulnerabilityAlerts": {
19+
"minimumReleaseAge": null
20+
},
1521
"autoApprove": true,
1622
"labels": ["Dependencies", "Renovate"],
1723
"packageRules": [

.yarnrc.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,6 @@
11
nodeLinker: node-modules
22
npmRegistryServer: 'https://registry.npmjs.org'
33
enableGlobalCache: true
4+
enableScripts: false
5+
npmMinimalAgeGate: 7d
6+
defaultSemverRangePrefix: ''

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
"release:alpha:latest": "lerna publish --exact --force-publish --conventional-commits --conventional-prerelease --preid alpha",
2020
"release:beta:latest": "lerna publish --exact --force-publish --conventional-commits --conventional-prerelease --preid beta",
2121
"release:next": "lerna publish --dist-tag next --exact --force-publish --conventional-commits --conventional-prerelease --preid alpha",
22-
"prepare": "husky",
22+
"postinstall": "husky",
2323
"commit": "npx cz",
2424
"co": "npx cz",
2525
"update": "yarn upgrade-interactive"

0 commit comments

Comments
 (0)