Repository navigation
Expand file tree
/
Copy path.npmrc
More file actions
55 lines (43 loc) · 2.22 KB
/
Copy path.npmrc
File metadata and controls
55 lines (43 loc) · 2.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
# Peer dependencies — fail on missing or mismatched peers
strict-peer-dependencies=true
# Workspace safety — no circular deps between workspace packages
disallow-workspace-cycles=true
# Workspace protocol — `pnpm add` in workspace always writes workspace:* refs
save-workspace-protocol=rolling
# Engine enforcement — fail if a package needs a different Node version
engine-strict=true
# Exact pnpm version — everyone must use the version in packageManager field
package-manager-strict-version=true
# Build script security — fail if any dep runs install scripts not in onlyBuiltDependencies
strict-dep-builds=true
# Deps sync check — fail pnpm run/exec if node_modules doesn't match lockfile
verify-deps-before-run=error
# Supply chain — block packages published less than 24h ago
minimum-release-age=1440
# Exclude known-good packages from minimum release age check
minimum-release-age-exclude=@base-ui/react
minimum-release-age-exclude[]=eslint-plugin-astro-pipeline
minimum-release-age-exclude[]=g3ts-eslint-plugin-astro-pipeline
minimum-release-age-exclude[]=g3ts-astro-nuasite-checks
minimum-release-age-exclude[]=g3ts-astro-sitemap-checks
minimum-release-age-exclude[]=g3ts-astro-robots-checks
minimum-release-age-exclude[]=g3ts-astro-llms-checks
minimum-release-age-exclude[]=g3ts-astro-llms
minimum-release-age-exclude[]=g3ts-astro-sitemap-auditor
minimum-release-age-exclude[]=g3ts-astro-robots-auditor
minimum-release-age-exclude[]=g3ts-astro-llms-auditor
minimum-release-age-exclude[]=g3ts-astro-llms-generator
minimum-release-age-exclude[]=g3ts-eslint-plugin-astro-i18n-policy
minimum-release-age-exclude[]=g3ts-eslint-plugin-astro-media-policy
minimum-release-age-exclude[]=g3ts-astro-media-assets
minimum-release-age-exclude[]=@nuasite/checks
# Supply chain — block transitive deps from using git repos or tarball URLs
block-exotic-subdeps=true
# Supply chain — warn if a package lost its npm provenance signatures
# Set to "no-downgrade" to hard-fail (blocked by undici-types losing provenance as of 2026-03)
trust-policy=warn
# Version pinning — `pnpm add` writes exact versions, no ^ or ~
save-prefix=
# Hoisting — explicit about defaults (pnpm v10 already strict, but be clear)
public-hoist-pattern=
shamefully-hoist=false