Files
franalgaba__grimoire/.npmrc
T
Fran Algaba fa20ce9e63 Mitigate axios supply-chain compromise (#82)
* Mitigate axios supply-chain compromise (CVE-2026-03-31)

Pin axios to 1.13.5 via overrides to prevent resolution of compromised
1.14.1/0.30.4 versions. Add bunfig.toml with minimumReleaseAge=604800
(7 days) and .npmrc min-release-age=7 as defense-in-depth against
future supply-chain attacks.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Add changeset for axios supply-chain mitigation

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 10:58:59 +02:00

2 lines
18 B
Plaintext