docs: Add dependency cooldown docs (#209)

* docs: Add dependency cooldown docs

* fix: Remove unnecessary params

* Update docs/dependency-cooldown.md

Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>

* fix: Cooldown guarantees

---------

Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
This commit is contained in:
Abhisek Datta
2026-04-08 17:19:30 +00:00
committed by GitHub
co-authored by Sahil Bansal
parent dbe968dec6
commit a128a60982
2 changed files with 33 additions and 0 deletions
+2
View File
@@ -118,6 +118,7 @@ npm i safedep-test-pkg@0.1.3
| **Sandboxing** | Enforces least privilege using OS native sandboxing to contain installation scripts. |
| **Dependency Analysis** | Deep scans of direct and transitive dependencies before they hit your disk. |
| **Event Logging** | Keeps a verifiable audit trail of all installed packages. |
| **Dependency Cooldown** | Blocks package versions published within a configurable time window, reducing exposure to supply chain attacks. |
| **Zero Config** | Works out of the box with sensible security defaults. |
| **Cross-Shell** | Seamlessly integrates with Zsh, Bash, Fish, and more. |
@@ -209,6 +210,7 @@ Security is our first class requirement. PMG builds are reproducible and signed.
## User Guide
* [Trusted Packages Configuration](docs/trusted-packages.md)
* [Dependency Cooldown](docs/dependency-cooldown.md)
* [Proxy Mode Architecture](docs/proxy-mode.md)
* [Sandboxing Details](docs/sandbox.md)
+31
View File
@@ -0,0 +1,31 @@
# Dependency Cooldown
Dependency cooldown filters package versions published within a configurable time window out of registry metadata responses during version resolution. This reduces exposure to supply chain attacks by ensuring the package manager normally only resolves versions that have been available for a minimum number of days.
## How It Works
When cooldown is enabled, PMG intercepts package metadata responses from the registry and strips versions published within the cooldown window. If the requested version range allows an older eligible release, the resolver falls back to it automatically. If no eligible version satisfies the request, the install fails.
Cooldown is enforced through metadata filtering and does not apply to direct tarball installs or workflows that already have a resolved tarball URL (e.g., lockfile or cache scenarios).
## Configuration
Dependency cooldown is configured in `config.yml`. See [config template](../config/config.template.yml) for the full schema. If you don't have a `config.yml` file, create one by running `pmg setup install`.
```yaml
dependency_cooldown:
enabled: true
days: 5
```
## CLI Override
Use `--skip-dependency-cooldown` to disable cooldown enforcement for a single invocation without changing the config file:
```bash
pmg --skip-dependency-cooldown npm install express
```
## Requirements
Dependency cooldown requires [proxy mode](proxy-mode.md) to be enabled. It is currently supported for npm packages.