JamieMason / JamieMason/syncpack
feat(update): add minimum age option
- Dominant language
- Rust
- Stars
- 2.1k
- Forks
- 72
- PR merge metrics
- No merged PRs in 30d
Description
### Description
So this is trending causing hysteria and finger pointing.
- https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised
- https://news.ycombinator.com/item?id=45260741
Something that came out of the comment thread was to limit updates to packages that are at least of a certain age.
What's the chance we can explore this for syncpack?
### Suggested Solution
unsure?
### Optional comments
_No response_
### Code of Conduct
- [x] I agree to follow the [Code of Conduct](https://github.com/JamieMason/syncpack/blob/main/CODE_OF_CONDUCT.md)
Contributor guide
Research direction
The issue names no files, tests, or entry points; start by locating syncpack’s update-related option handling and existing tests. Define the minimum package-age behavior and verify the chosen interface and edge cases with tests, including a clear indication of what completion means.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100