From db882c0a2e8b1b41afa9ec6ef6d702cbfeffa3c5 Mon Sep 17 00:00:00 2001 From: Noah Schatz Date: Fri, 25 Sep 2026 20:20:20 +0000 Subject: [PATCH] Exempt @cosyte packages from the 24-hour release-age floor OPERATOR: "I need every single package on v0.1.x and published. I need extensive marketing material to get cosyte off the ground and start bringing in business." and "Nothing is off limits. Create a marketing repo as needed to get cosyte MOVING!" Among options put to them for the v0.1 launch, the operator chose to exempt @cosyte/* from the 24-hour release-age floor and keep it for every third-party package. Claude-Session: https://claude.ai/code/session_01U24bnHKNxQWMxmfN7ny7w9 --- pnpm-workspace.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index b3344f7..b61f38c 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -5,6 +5,7 @@ # delayed resolution most likely never sees the bad version at all. If a range # has no version old enough, pnpm refuses the install; that refusal IS the # control working and is never to be answered by lowering the number. +# @cosyte is exempt by operator decision; every third-party package keeps the floor. # # trustPolicy no-downgrade refuses a resolution that would move a package # backwards, which is how a downgrade attack reintroduces a fixed advisory. @@ -14,4 +15,7 @@ # separate housekeeping choice: an older pnpm ignores the keys entirely and # leaves a settings file that decorates rather than defends. minimumReleaseAge: 1440 +minimumReleaseAgeExclude: + # reason: first-party @cosyte package, exempt from the floor by operator decision + - "@cosyte/*" trustPolicy: no-downgrade