chore: deny esbuild's install script and check allowScripts against the lockfile - #85
Merged
Merged
Conversation
npm 11 skips a dependency's install script unless allowScripts names it, and reports the skip as a warning. An approval pinned to a version stops matching as soon as the lockfile moves that package, and a new dependency with an install script matches nothing, so both cases leave every job green. The new suite checks that each pinned approval matches the version the lockfile installs, that every entry names a package the lockfile installs with an install script, and that every install script CI would run is approved or denied. Packages the lockfile limits to other operating systems are left out: they never install on Linux, where CI runs. Against the manifest and lockfile of 1bf2da4, where the esbuild pin had fallen behind, the pin check fails on esbuild@0.28.1 while the lockfile installs 0.28.2. A moved-back pin, a removed entry and an entry for a package that is not installed each fail exactly one case. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
esbuild's platform binary arrives as an optional dependency. Its install script checks that binary and fetches one only when the optional dependency is missing, and the fixtures use the JavaScript API, which resolves the binary from that dependency at run time. Both fixtures build with the script never having run. A name-only denial also cannot fall behind the lockfile the way a pinned approval does. That leaves one pinned approval, @playwright/browser-chromium, whose script downloads the browser the web extension host lane drives. The //allowScripts note now says so. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Denies esbuild's install script, and adds a test that fails when
allowScriptsfalls out of step with the lockfile.Why
npm 11 skips unapproved install scripts with a warning, not an error. The esbuild approval was pinned to 0.28.1 while the lockfile installed 0.28.2, so its install script was skipped in the Node 24 and 26 jobs for weeks and every job stayed green. The same happens to any pinned approval when the lockfile moves that package, and to any new dependency that brings an install script.
esbuild does not need its install script here. Its platform binary arrives as an optional dependency; the script checks that binary and fetches one only when the dependency is missing. The fixtures use esbuild's JavaScript API, which resolves the binary from the optional dependency at run time.
Changes
allowScripts: esbuild is denied by name ("esbuild": false), and a name-only entry cannot fall behind the lockfile.@playwright/browser-chromium@1.63.0stays approved, since its script downloads the browser the web extension host lane drives. The//allowScriptsnote is rewritten to match.tests/allow-scripts.test.ts: each pinned approval must match the version the lockfile installs, each entry must name a package the lockfile installs with an install script, and every install script CI would run must be approved or denied. A failure names the fix (npm install-scripts approve <pkg>).Verification
esbuild@0.28.1 is pinned but the lockfile installs 0.28.2) and passes here.npm install-scripts lsreports no unreviewed install scripts, andnpm install-scripts prune --dry-runfinds no unused entries.npm run qualitypasses.allowScripts.🤖 Generated with Claude Code