Minimum package age
Minimum package age controls how long a new upstream release waits before Ravenstash can serve it. Many supply-chain attacks depend on a compromised or malicious release reaching automated builds before maintainers and security researchers can react. A delay creates time for that release to be reported, removed, or flagged by security scanning.
Default behavior
Section titled “Default behavior”- Default minimum age: 24 hours.
- Supported range: 0–4320 hours.
- A value of 0 allows new releases immediately without disabling the upstream.
PyPI and npm decisions use upstream release metadata. Maven uses Maven Central Last-Modified information when available.
Per-connection values
Section titled “Per-connection values”Each mirror connected to a PyPI, npm, or Maven repository keeps its own package-age settings. Changing the default for a mirror does not silently change repositories that already use it.
Direct access to a mirror uses that mirror’s defaults. To change them, open the mirror’s Private mirror tab and choose Change minimum age.
Change one or several connections
Section titled “Change one or several connections”Open a repository’s Upstreams settings to edit the selected connection. You can apply the same value to several selected connections. Each connection can still be adjusted independently afterward.
Allowing new releases immediately affects only the connections you update; it does not remove an upstream.
Choosing a value
Section titled “Choosing a value”Consider release cadence, lockfile practices, emergency update needs, and your tolerance for newly published dependencies. A 24-hour delay is a practical starting point for many teams; security-sensitive projects may choose longer.

