Enforce the npm version floor with legacy clients (#411)

`devEngines` is ignored by npm releases such as `10.8.2`, so those
clients can install dependencies without applying the seven-day
`min-release-age` setting added in #401. Declare the same minimum in
`engines.npm` and enable `engine-strict` to make that legacy installer
requirement fatal. Keep `devEngines` for its earlier checks on newer npm
versions, and pin the build and checksum workflows to Node.js `24.19.0`
so their bundled `npm` supports the policy.

Related: astral-sh/setup-uv#1026 and astral-sh/ruff#27844 enforce the
same legacy-aware `npm` version floor. astral-sh/ruff-action#400 covers
Dependabot's update cooldown, and astral-sh/ruff-action#402 separately
verifies registry signatures and available provenance.

---------

Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
This commit is contained in:
zaniebot
2026-08-20 17:36:55 +02:00
committed by GitHub
co-authored by zaniebot
parent 848ccd1cb2
commit 46b5b9699e
4 changed files with 8 additions and 1 deletions
+3
View File
@@ -5,6 +5,9 @@
"type": "module",
"description": "A GitHub Action to run Ruff, an extremely fast Python linter and code formatter.",
"main": "dist/ruff-action/index.cjs",
"engines": {
"npm": ">=11.10.0"
},
"devEngines": {
"packageManager": {
"name": "npm",