security: set npmMinimalAgeGate to 7d - #6
OffenseTeacher wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 33e78b2. Configure here.
|
|
||
| nmSelfReferences: false | ||
|
|
||
| npmMinimalAgeGate: 7d |
There was a problem hiding this comment.
Age gate unsupported on Yarn
High Severity
This change adds npmMinimalAgeGate: 7d, but the project runs Yarn 3.6.4 via yarnPath and packageManager. That option is implemented in newer Berry releases (from 4.10 onward), not in the pinned 3.6.4 bundle, so installs are not blocked for packages younger than seven days and the intended supply-chain control does not run.
Reviewed by Cursor Bugbot for commit 33e78b2. Configure here.


Summary
Sets
npmMinimalAgeGate: 7din.yarnrc.ymlto prevent Yarn from installing npm packages published less than 7 days ago.This is a defence against supply chain worm attacks (Shai-Hulud, Sept 2025 / Glassworm 2026) that inject malicious post-install scripts into newly published popular packages.
Part of org-wide security hardening across all Yarn Berry repos.