Skip to content

Implement dependency cooldowns in composer #12633

@phront

Description

@phront

Is your feature request related to a problem? Please describe.
I have recently read blog post We should all be using dependency cooldowns, but not found the feature in composer. It would be nice to have dependency cooldown option in composer

Describe the solution you'd like
Dependency cooldowns are a free, easy, and incredibly effective way to mitigate the large majority of open source supply chain attacks. More individual projects should apply cooldowns (via tools like Dependabot and Renovate) to their dependencies, and packaging ecosystems should invest in first-class support for cooldowns directly in their package managers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels
    No fields configured for Feature.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions