Files
fleet/handbook
2607475fae Add "Why enforce a minimum release age for npm packages?" to handbook (#45257)
## Summary
- Adds a new entry to the "Why this way?" handbook page explaining why
Fleet enforces `min-release-age` in `.npmrc` as a supply-chain security
measure.
- Covers the rationale (short delay catches compromised packages before
they're pulled), why the delay is intentionally short (30 minutes), and
why Fleet requires npm v11.10.0+ with policy-based compliance.

Built for [Mike
McNeil](https://fleetdm.slack.com/archives/C071NNMSP2R/p1778605151595179?thread_ts=1778604726.978409&cid=C071NNMSP2R)
by [Kilo for Slack](https://kilo.ai/slack)

---------

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Co-authored-by: Mike McNeil <mikermcneil@users.noreply.github.com>
2026-05-13 15:15:52 -07:00
..
2026-05-07 16:52:58 +01:00

Welcome to Fleet

Introduction

The Fleet handbook is the living source of truth for how we run the company. This handbook is open to the world and feedback and contributions are welcome from everyone. Feel free to click "Edit this page" to suggest an improvement anywhere you see fit. (The right reviewer will be automatically notified, and will reply to you promptly. Your change will go live on the website ≈10 minutes after it is merged.)