mirror of
https://github.com/astral-sh/setup-uv.git
synced 2026-09-02 21:59:22 +00:00
CI already disables npm lifecycle scripts, but ordinary installs from the repository still run them. Set `ignore-scripts = true` in `.npmrc` so developer and maintenance installs use the same default. Keep the existing seven-day `min-release-age` policy for new resolutions. Require `npm>=11.10.0` through `engines.npm` and `engine-strict`, while retaining `devEngines` for newer clients; older installers can otherwise ignore `devEngines` and the age setting. Pin the build and checksum workflows to Node.js `24.19.0` so their bundled `npm` supports the policy. Explicit project commands such as `npm run package` remain available. Related: astral-sh/ruff-action#401 applies the matching `npm` defaults, and astral-sh/ruff-action#411 adds the same legacy-aware version floor. astral-sh/ruff#27837 applies the install-script default to Ruff's JavaScript projects. astral-sh/setup-uv#1027 separately adds registry-signature and provenance verification. --------- Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
4 lines
63 B
Plaintext
4 lines
63 B
Plaintext
engine-strict = true
|
|
ignore-scripts = true
|
|
min-release-age = 7
|