Skip to content

Support dependency-cooldowns / minimum-artifact-age to mitigate short-lived supply chain attacks #3757

@rtyley

Description

@rtyley

See:

For Scala Steward, this issue is a revisit of a few old issues/PRs:

Sources of artifact-age data

Unfortunately, Maven does not currently encode a way to tell an artifact's publication date:

https://stackoverflow.com/q/69790966/438886

Questions

  • How do we want to configure this? What should the configuration look like?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions