pnpm-workspace.yamlminimumReleaseAgeExclude has accumulated ~30 version-pinned exclusions (pnpm 11.12, FullCalendar 7.0.1, the 2026-07-22 refresh, the Angular 22.0.6/22.0.8 patch train…). Each comment says "drop once older than the cutoff" — they all are now. Dead entries make it hard to see which exclusions are live.
Also minimumReleaseAgeStrict is false, so pnpm silently auto-adds exclusions for young direct deps during installs (that's how the Angular patch-train block appeared). Setting it true makes skipping the release-age gate an explicit, reviewed decision — a supply-chain improvement.
Acceptance criteria
remove every exclusion for a version older than the cutoff (and versions no longer in the lockfile)
decide minimumReleaseAgeStrict: true (recommended) and document the "how to bump a <24h release on purpose" step in the file comment
pnpm install --frozen-lockfile green in CI
Size: XS.
Filed from the 2026-10-02 spikersoft-angular pnpm outdated changelog review.
## Why
`pnpm-workspace.yaml` `minimumReleaseAgeExclude` has accumulated ~30 version-pinned exclusions (pnpm 11.12, FullCalendar 7.0.1, the 2026-07-22 refresh, the Angular 22.0.6/22.0.8 patch train…). Each comment says "drop once older than the cutoff" — they all are now. Dead entries make it hard to see which exclusions are live.
Also `minimumReleaseAgeStrict` is **false**, so pnpm silently *auto-adds* exclusions for young direct deps during installs (that's how the Angular patch-train block appeared). Setting it **true** makes skipping the release-age gate an explicit, reviewed decision — a supply-chain improvement.
## Acceptance criteria
- [ ] remove every exclusion for a version older than the cutoff (and versions no longer in the lockfile)
- [ ] decide `minimumReleaseAgeStrict: true` (recommended) and document the "how to bump a <24h release on purpose" step in the file comment
- [ ] `pnpm install --frozen-lockfile` green in CI
Size: **XS**.
---
_Filed from the 2026-10-02 spikersoft-angular `pnpm outdated` changelog review._
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Why
pnpm-workspace.yamlminimumReleaseAgeExcludehas accumulated ~30 version-pinned exclusions (pnpm 11.12, FullCalendar 7.0.1, the 2026-07-22 refresh, the Angular 22.0.6/22.0.8 patch train…). Each comment says "drop once older than the cutoff" — they all are now. Dead entries make it hard to see which exclusions are live.Also
minimumReleaseAgeStrictis false, so pnpm silently auto-adds exclusions for young direct deps during installs (that's how the Angular patch-train block appeared). Setting it true makes skipping the release-age gate an explicit, reviewed decision — a supply-chain improvement.Acceptance criteria
minimumReleaseAgeStrict: true(recommended) and document the "how to bump a <24h release on purpose" step in the file commentpnpm install --frozen-lockfilegreen in CISize: XS.
Filed from the 2026-10-02 spikersoft-angular
pnpm outdatedchangelog review.