Enforce the npm version floor with legacy clients (#411)

`devEngines` is ignored by npm releases such as `10.8.2`, so those
clients can install dependencies without applying the seven-day
`min-release-age` setting added in #401. Declare the same minimum in
`engines.npm` and enable `engine-strict` to make that legacy installer
requirement fatal. Keep `devEngines` for its earlier checks on newer npm
versions, and pin the build and checksum workflows to Node.js `24.19.0`
so their bundled `npm` supports the policy.

Related: astral-sh/setup-uv#1026 and astral-sh/ruff#27844 enforce the
same legacy-aware `npm` version floor. astral-sh/ruff-action#400 covers
Dependabot's update cooldown, and astral-sh/ruff-action#402 separately
verifies registry signatures and available provenance.

---------

Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
This commit is contained in:
zaniebot
2026-08-20 17:36:55 +02:00
committed by GitHub
co-authored by zaniebot
parent 848ccd1cb2
commit 46b5b9699e
4 changed files with 8 additions and 1 deletions
+1
View File
@@ -1,2 +1,3 @@
engine-strict = true
ignore-scripts = true
min-release-age = 7
+1 -1
View File
@@ -1 +1 @@
24
24.19.0
+3
View File
@@ -31,6 +31,9 @@
"js-yaml": "^4.1.1",
"ts-jest": "^29.4.6",
"typescript": "^5.9.3"
},
"engines": {
"npm": ">=11.10.0"
}
},
"node_modules/@actions/core": {
+3
View File
@@ -5,6 +5,9 @@
"type": "module",
"description": "A GitHub Action to run Ruff, an extremely fast Python linter and code formatter.",
"main": "dist/ruff-action/index.cjs",
"engines": {
"npm": ">=11.10.0"
},
"devEngines": {
"packageManager": {
"name": "npm",