# needed to prevent bad npm that has min-release-age but not exclude
engine-strict=true

min-release-age=14

# No exemptions. An exemption turns the 14-day publish-time gate off for a
# package -- the gate that is the repo's defence against a freshly compromised
# release (litellm #2796/#2810, the Mini Shai-Hulud worm) -- so it carries a
# reason, the version that needs it and an expiry date, and it is deleted the
# day the gate would have cleared that version on its own. website/.npmrc shows
# the shape; scripts/ci/source_guards/npmrc_age_gate_exemptions_dated.py refuses
# an undated one.
#
# The lightningcss and postcss exemptions that used to live here were the
# undated leftovers of that sweep: every version either lockfile resolves
# (lightningcss 1.32.0 / 1.33.0, postcss 8.5.23) has been published for months,
# `npm ci` installs exactly those, and even both packages' current latest
# releases are older than the gate -- so the exemptions bought nothing and only
# widened the hole.
