Skip to content

chore(deps): limit dependency updates to older releases#431

Open
Abhijeet Prasad (AbhiPrasad) wants to merge 1 commit into
mainfrom
abhi-chore-uv-exclude-newer-deps
Open

chore(deps): limit dependency updates to older releases#431
Abhijeet Prasad (AbhiPrasad) wants to merge 1 commit into
mainfrom
abhi-chore-uv-exclude-newer-deps

Conversation

@AbhiPrasad
Copy link
Copy Markdown
Member

Configure uv exclude-newer to avoid packages uploaded in the last five days during weekly dependency updates.

Teach the matrix latest updater to honor the same cutoff when selecting provider pins from PyPI.

This should help against supply chain attacks when we run our dependency updates in the start of each week.

Configure uv exclude-newer to avoid packages uploaded in the last five days during weekly dependency updates.

Teach the matrix latest updater to honor the same cutoff when selecting provider pins from PyPI.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant