Don't upgrade packages less than 7 days old
envgap__python-telegram-bot__python-telegram-bot-5195
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
1a83d47fb32e0d5892ef208309e4e03721539f39- Manifest
pyproject.toml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
python-telegram-bot/python-telegram-bot #5195 · read the original issue
There have been many supply chain attacks recently involving compromised dependencies. E.g. the recent axios attack ([this video](https://youtu.be/yiLIZLPNEm8?si=ie4XgFDVqfFhLucw) does a nice job explaining that situation). In general, good security practices for dependencies state that you shouldn't update your dependencies instantly - having a buffer period of something like 7 days allows the community to audit packages for malicious behaviour. ### Proposal Set the [`minimumReleaseAge` config option in Renovate.](https://docs.renovatebot.com/key-concepts/minimum-release-age/#minimum-release-age). Additionally, they also recommend setting that in your package manager for transitive dependencies and for lockfiles. `pip` does not have support for such a thing, but `uv` does via the [`exclude-newer` flag ](https://docs.astral.sh/uv/reference/settings/#exclude-newer). It's unlikely that our users would be affected by security bugs mostly because our release cycle is rather long. This change would benefit anyone developing for the library, because we would be pulling in the latest changes from master. What do you think, is this a reasonable thing to do or is it rather aggressive?
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]