Skip to content

chore(deps): ツール更新の公開待機期間を延ばす#147

Merged
nkoji21 merged 1 commit into
mainfrom
chore/harden-tool-release-age
May 30, 2026
Merged

chore(deps): ツール更新の公開待機期間を延ばす#147
nkoji21 merged 1 commit into
mainfrom
chore/harden-tool-release-age

Conversation

@nkoji21

@nkoji21 nkoji21 commented May 30, 2026

Copy link
Copy Markdown
Owner

Summary

依存ツールの新規リリースを即時採用しないようにして、サプライチェーンリスクを下げます。

Changes

  • mise に minimum_release_age = "14d" を追加
  • Renovate の minimumReleaseAge を 14 日に延長
  • Renovate の vulnerability alerts を明示的に有効化し、security ラベルを付与

Notes

Renovate の脆弱性修正 PR は通常更新の公開待機期間とは別に扱われます。

Co-Authored-By: Claude <noreply@anthropic.com>
@nkoji21 nkoji21 marked this pull request as ready for review May 30, 2026 10:24
@nkoji21 nkoji21 merged commit 69a9bd9 into main May 30, 2026
3 checks passed
@nkoji21 nkoji21 deleted the chore/harden-tool-release-age branch May 30, 2026 10:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant