mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
docs: Add dependency cooldown docs (#209)
* docs: Add dependency cooldown docs * fix: Remove unnecessary params * Update docs/dependency-cooldown.md Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * fix: Cooldown guarantees --------- Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
This commit is contained in:
co-authored by
Sahil Bansal
parent
dbe968dec6
commit
a128a60982
@@ -118,6 +118,7 @@ npm i safedep-test-pkg@0.1.3
|
||||
| **Sandboxing** | Enforces least privilege using OS native sandboxing to contain installation scripts. |
|
||||
| **Dependency Analysis** | Deep scans of direct and transitive dependencies before they hit your disk. |
|
||||
| **Event Logging** | Keeps a verifiable audit trail of all installed packages. |
|
||||
| **Dependency Cooldown** | Blocks package versions published within a configurable time window, reducing exposure to supply chain attacks. |
|
||||
| **Zero Config** | Works out of the box with sensible security defaults. |
|
||||
| **Cross-Shell** | Seamlessly integrates with Zsh, Bash, Fish, and more. |
|
||||
|
||||
@@ -209,6 +210,7 @@ Security is our first class requirement. PMG builds are reproducible and signed.
|
||||
## User Guide
|
||||
|
||||
* [Trusted Packages Configuration](docs/trusted-packages.md)
|
||||
* [Dependency Cooldown](docs/dependency-cooldown.md)
|
||||
* [Proxy Mode Architecture](docs/proxy-mode.md)
|
||||
* [Sandboxing Details](docs/sandbox.md)
|
||||
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
# Dependency Cooldown
|
||||
|
||||
Dependency cooldown filters package versions published within a configurable time window out of registry metadata responses during version resolution. This reduces exposure to supply chain attacks by ensuring the package manager normally only resolves versions that have been available for a minimum number of days.
|
||||
|
||||
## How It Works
|
||||
|
||||
When cooldown is enabled, PMG intercepts package metadata responses from the registry and strips versions published within the cooldown window. If the requested version range allows an older eligible release, the resolver falls back to it automatically. If no eligible version satisfies the request, the install fails.
|
||||
|
||||
Cooldown is enforced through metadata filtering and does not apply to direct tarball installs or workflows that already have a resolved tarball URL (e.g., lockfile or cache scenarios).
|
||||
|
||||
## Configuration
|
||||
|
||||
Dependency cooldown is configured in `config.yml`. See [config template](../config/config.template.yml) for the full schema. If you don't have a `config.yml` file, create one by running `pmg setup install`.
|
||||
|
||||
```yaml
|
||||
dependency_cooldown:
|
||||
enabled: true
|
||||
days: 5
|
||||
```
|
||||
|
||||
## CLI Override
|
||||
|
||||
Use `--skip-dependency-cooldown` to disable cooldown enforcement for a single invocation without changing the config file:
|
||||
|
||||
```bash
|
||||
pmg --skip-dependency-cooldown npm install express
|
||||
```
|
||||
|
||||
## Requirements
|
||||
|
||||
Dependency cooldown requires [proxy mode](proxy-mode.md) to be enabled. It is currently supported for npm packages.
|
||||
Reference in New Issue
Block a user