Skip to content

Conversation

@Ariiellus
Copy link

Description

Following discussion in #1183 to increase security measures in the development workflow. This PR upgrades the current yarn v3.2.3 version to the latest v4.10.3 to enable npmMinimalAgeGate.

npmMinimalAgeGate improves supply chain security by introducing a delay before newly published npm packages can be installed, providing researchers time to identify and report malicious releases.

Additional Information

Related Issues

_Closes #1183 _

Your ENS/address:
Ariiellus.eth
0x6d465d2081b799770d0ce7e755d8db1665903ffb

@technophile-04
Copy link
Collaborator

Hey @Ariiellus, Thanks for the PR! Can you tell the steps you followed to migrate to v4?

I think we just need to do:

yarn set version berry
yarn install

And yarn automatically migrates / updates the file. Asking this because I tried running the above command and it removed the plugs which we have configured and updated the yarn.lock file as well. Can you please push those changes as well?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants