# Supply-chain cooldown. Refuse any package version published less than 7 days # ago, so a compromised release has time to be caught and yanked before it can # reach a lockfile here. Every npm compromise of 2026 — axios (live 3 hours), # jscrambler (minutes), the TanStack and @antv waves — was pulled well inside # this window. # # Requires npm >= 11.10. On older npm this key is silently IGNORED, not an # error: if `npm config get min-release-age` prints `undefined`, it is doing # nothing. This repo was on npm 10.9.8 when the line was added, so check before # trusting it. min-release-age=7 engine-strict=true # Deliberately NOT setting `ignore-scripts=true`. It reads like free hardening # and it is not: ffmpeg-static fetches its binary from an `install` script, and # without it backend/tape-to-mp4.mjs breaks in production. It has also stopped # being much of a defense — the Miasma worm fires from binding.gyp during # node-gyp builds, and later jscrambler variants moved to import-time execution # specifically to get around this flag. The cooldown above is the control that # actually pays for itself.