Skip to content

High-risk trust downgrade for "effect@4.0.0-beta.70" (possible package takeover) #786

@yusifaliyevpro

Description

@yusifaliyevpro

Hi,

I get this issue because of my global pnpm configuration trustPolicy: "no-downgrade"

$ pnpx react-doctor@latest --verbose
C:\Users\yusif\AppData\Local\pnpm-cache\dlx\7d3ca75fedce9ba58700013dd0f7e26a6e19b157dfed73ed3c4176a590bc7537\19eb56f3dc8-3418:
[ERR_PNPM_TRUST_DOWNGRADE] High-risk trust downgrade for "effect@4.0.0-beta.70" (possible package takeover)

This error happened while installing the dependencies of react-doctor@0.5.1

Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Earlier versions had trusted publisher, but this version has provenance attestation. A trust downgrade may indicate a supply chain incident.
Progress: resolved 17, reused 17, downloaded 0, added 0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions