AWS Security ChangesHomeSearch

AWS linux: Document npm min-release-age dependency cooldown on AL2027

Service: linux · 2026-09-27 · Documentation medium

File: linux/al2027/ug/nodejs-security.md · Type: supply-chain

Summary

Adds guidance that AL2027 sets min-release-age=1 in /etc/npmrc by default, explains precedence and per-command override, and recommends npm audit for known vulnerabilities.

Security assessment

Documents a default security configuration (min-release-age=1) that mitigates short-lived supply chain attacks via malicious npm packages, plus npm audit usage; it is hardening/best-practice documentation rather than a specific vulnerability fix.

Evidence

+Amazon Linux 2027 turns on npm's dependency cooldown by default. The _min-release-age_ option (npm 11.10.0 and later) tells npm to resolve only package versions that have been publicly available for at least the given number of days, so a just-published — and possibly compromised — release cannot enter your dependency tree the moment it lands on the registry. Most malicious packages are detected and removed within hours, so even a short cooldown eliminates exposure to the majority of short-lived supply chain attacks. AL2027 sets a one-day cooldown in the system-wide npm configuration file, _/etc/npmrc_ : 

Diff

diff --git a/linux/al2027/ug/nodejs-security.md b/linux/al2027/ug/nodejs-security.md
index f32ebee11..715a531d7 100644
--- a//linux/al2027/ug/nodejs-security.md
+++ b//linux/al2027/ug/nodejs-security.md
@@ -10,0 +11,17 @@ When using Node.js and _npm_ on AL2027, follow the upstream [Node.js security be
+Amazon Linux 2027 turns on npm's dependency cooldown by default. The _min-release-age_ option (npm 11.10.0 and later) tells npm to resolve only package versions that have been publicly available for at least the given number of days, so a just-published — and possibly compromised — release cannot enter your dependency tree the moment it lands on the registry. Most malicious packages are detected and removed within hours, so even a short cooldown eliminates exposure to the majority of short-lived supply chain attacks. AL2027 sets a one-day cooldown in the system-wide npm configuration file, _/etc/npmrc_ : 
+    
+    
+    min-release-age=1
+
+The value is expressed in days, so by default every npm install and npm update on the instance ignores versions published in the last 24 hours. You do not need to edit _/etc/npmrc_ to change this: it is npm's lowest-precedence configuration source, and any higher-precedence source overrides it — the command line, npm_config_* environment variables, a project-level _.npmrc_ , or a user-level _~/.npmrc_. Raise the value for a stricter policy, or set it to 0 to disable the cooldown for a single command: 
+    
+    
+    npm install --min-release-age=0 package-name
+
+Use that per-command override when you need a security fix that was published inside the cooldown window. Run 
+    
+    
+    npm audit
+
+to identify which dependencies have known vulnerabilities and require immediate updating. Note that if the cooldown leaves no eligible version for a dependency, npm fails the command rather than silently selecting a different release — override the cooldown for that install or pin the dependency explicitly. 
+