Skip to content

ci: add uv package install cooldown#63

Open
bhimrazy wants to merge 3 commits into
Lightning-AI:mainfrom
bhimrazy:ci/supply-chain-cooldown
Open

ci: add uv package install cooldown#63
bhimrazy wants to merge 3 commits into
Lightning-AI:mainfrom
bhimrazy:ci/supply-chain-cooldown

Conversation

@bhimrazy

@bhimrazy bhimrazy commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds a CI-only supply-chain guard for uv-based workflows: the resolver refuses PyPI releases published within the last 2 days, so fresh suspicious uploads have time to be detected or yanked before landing in CI.

ref: Lightning-AI/pytorch-lightning#21722.

Env var Value Scope
UV_EXCLUDE_NEWER "2 days" uv-based CI jobs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants