chore: enforce npm min-release-age dependency cooldown - #77
Conversation
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
|
@cursor review |
Co-Authored-By: Steven Zhang <szhang@launchdarkly.com>
64de6ca to
2ded8dc
Compare
Co-Authored-By: Steven Zhang <szhang@launchdarkly.com>
Co-Authored-By: Steven Zhang <szhang@launchdarkly.com>
| variations: [ | ||
| {os: ubuntu-latest, node: latest}, | ||
| {os: ubuntu-latest, node: 18} | ||
| {os: ubuntu-latest, node: 22} |
There was a problem hiding this comment.
🟡 Continuous integration no longer tests the oldest supported Node version
The build matrix no longer includes any older Node version ({os: ubuntu-latest, node: 22} replacing 18 at .github/workflows/ci.yml:19) even though the package still declares support down to Node 12, so breakage on older supported runtimes goes undetected.
Impact: Users on older but officially supported Node versions can receive a release that fails for them without any test having caught it.
Mismatch between declared engine range, contributing guide, and the CI matrix
CONTRIBUTING.md states "The project should be built and tested against the lowest compatible version, Node 12", and package.json declares "engines": {"node": ">= 12.0.0"}. After this change the matrix only covers latest and 22. Either the engines range / contributing guide should be updated to match the new minimum, or an older Node entry should be retained in the matrix.
Prompt for agents
The CI matrix in .github/workflows/ci.yml now only tests Node 'latest' and Node 22, but package.json declares engines node >= 12.0.0 and CONTRIBUTING.md states the project should be built and tested against the lowest compatible version (Node 12). Decide on the real minimum supported Node version and make the three sources consistent: update package.json engines and CONTRIBUTING.md if the minimum is being raised, or keep an older Node entry in the CI matrix that matches the declared minimum.
Was this helpful? React with 👍 or 👎 to provide feedback.
| @@ -0,0 +1,3 @@ | |||
| min-release-age=3 | |||
There was a problem hiding this comment.
🟡 New dependency-age safety delay is set far too short to have any effect
The waiting period before newly published packages may be installed is configured as 3 (min-release-age=3 in .npmrc:1), but this setting is measured in minutes, so brand-new package versions are accepted after only three minutes instead of the intended multi-day delay.
Impact: The protection against freshly published (potentially compromised) dependency versions is effectively disabled.
Units of the npm min-release-age setting
npm's min-release-age config is a number of minutes. A value of 3 means any version published more than 3 minutes ago is installable, which provides essentially no quarantine window. A 3-day delay would be 4320. The presence of min-release-age-exclude[] entries for launchdarkly-eventsource and launchdarkly-js-sdk-common (.npmrc:2-3) indicates the intent was a delay long enough that LaunchDarkly's own freshly released packages would otherwise be blocked — which only makes sense with a much larger value.
| min-release-age=3 | |
| min-release-age=4320 |
Was this helpful? React with 👍 or 👎 to provide feedback.
Co-Authored-By: Steven Zhang <szhang@launchdarkly.com>
Co-Authored-By: Steven Zhang <szhang@launchdarkly.com>
Requirements
Related issues
Supply chain hardening for legacy SDK repositories, mirroring js-core's yarn
npmMinimalAgeGate: 4320(3 days).Describe the solution you've provided
.npmrcwithmin-release-age=3(npm expresses this in days), so npm resolves only versions published more than 3 days ago. Unlike a Dependabot-level setting, this applies to every install — local development and CI alike.min-release-age-excludeexplicitly names the first-party packages this repo actually resolves (launchdarkly-eventsource,launchdarkly-js-sdk-common), so LaunchDarkly patches can be adopted immediately while third-party releases stay quarantined. Names are listed individually rather than pattern matched.npm@^12.0.0beforenpm install, so the gate applies to both PR builds and published releases.min-release-age-excludeneeds npm 12, which requires node >=22.22, so the older CI matrix entry is raised to node 22.Describe alternatives you've considered
Dependabot
cooldown— only governs Dependabot PRs, and these legacy repos aren't aiming to stay continuously updated.Additional context
Verified locally with npm 12:
npm installand the test suite pass with the gate active. CI is green.Link to Devin session: https://app.devin.ai/sessions/566f0d951dfa4568b67ad0c6c1cfb7c1
Requested by: @joker23
Note
Low Risk
Workflow and install-policy changes only; no runtime SDK logic, with a short delay before newly published third-party versions resolve.
Overview
Adds a 3-day npm install cooldown for third-party packages via
min-release-age=3in root andcontract-tests/.npmrc, matching js-core’s supply-chain posture.launchdarkly-eventsourceandlaunchdarkly-js-sdk-commonare excluded so first-party patches can install immediately.CI and release install
npm@^12.0.0beforenpm install(required formin-release-age-exclude). The CI matrix drops Node 18 in favor of Node 22 to satisfy npm 12’s Node requirement. The release workflow bumps global npm from 11.6.2 to ^12.0.0 as well.Reviewed by Cursor Bugbot for commit 2bdf06c. Bugbot is set up for automated code reviews on this repo. Configure here.