← Back to context

Comment by tjansen

5 hours ago

I wonder whether there is any tool that can prevent npm from downloading any package that has been published in the last month. While I miss out on possible fixes, this would prevent downloading some 3rd level dep that takes over my machine.

pnpm has added a new setting, minimumReleaseAge, enabled by default, just to try to mitigate these issues.