Files
zaniebotandzaniebot 46b5b9699e Enforce the npm version floor with legacy clients (#411)
`devEngines` is ignored by npm releases such as `10.8.2`, so those
clients can install dependencies without applying the seven-day
`min-release-age` setting added in #401. Declare the same minimum in
`engines.npm` and enable `engine-strict` to make that legacy installer
requirement fatal. Keep `devEngines` for its earlier checks on newer npm
versions, and pin the build and checksum workflows to Node.js `24.19.0`
so their bundled `npm` supports the policy.

Related: astral-sh/setup-uv#1026 and astral-sh/ruff#27844 enforce the
same legacy-aware `npm` version floor. astral-sh/ruff-action#400 covers
Dependabot's update cooldown, and astral-sh/ruff-action#402 separately
verifies registry signatures and available provenance.

---------

Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
2026-08-20 17:36:55 +02:00

2 lines
8 B
Plaintext