Skip to content

feat: read package manager configs to determine cooldown configuration #47

@anthonyscarfe

Description

@anthonyscarfe

There is growing consensus that package cooldowns are a strong and low cost mitigation for compromised dev packages in CI/CD and dev workstations. Achieving a specific configuration in centralised CI/CD is relatively straightforward, but difficult in distributed dev workstations.

A feature to audit the configuration of package managers and surface the effective cooldown in place on dev workstations would enable proactive management of a defensive posture alongside the response capabilities.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions