Unpinning the CLI keeps the previous install behavior, and leaving minimumReleaseAge in place for vulnerabilityAlerts means a malicious release can't be pulled in immediately.
Unpinning the CLI keeps the previous install behavior, and leaving minimumReleaseAge in place for vulnerabilityAlerts means a malicious release can't be pulled in immediately.