minimumReleaseAgeExclude updating bypasses security processes?
#41056
How are you running Renovate?A Mend.io-hosted app Which platform you running Renovate on?GitHub.com Which version of Renovate are you using?No response Please tell us more about your question or problemthe automatic updating of The By automating the bypassing of this mechanism, that protection is gone. If the supply chain attack is able to create a vulnerability alert, they can have their poisoned version installed immediately and automatically. Am I missing something? Logs (if relevant)No response |
Replies: 1 comment 2 replies
|
@geuben yeah it sounds like you're missing something. From the title of PR #40020 (emphasis mine):
Security updates should roll out faster than You can read more in my original discussion: |
@geuben yeah it sounds like you're missing something.
From the title of PR #40020 (emphasis mine):
Security updates should roll out faster than
minimumReleaseAge, because they are about resolving a security problem. Security updates have been vetted by GitHub and have low supply chain attack risk, versus the security improvement they are making.You can read more in my original discussion: