Skip to content

chore: deny esbuild's install script and check allowScripts against the lockfile - #85

Merged
kkdev92 merged 2 commits into
mainfrom
chore/install-script-review
Sep 29, 2026
Merged

kkdev92 merged 2 commits into
mainfrom
chore/install-script-review

Conversation

@kkdev92

@kkdev92 kkdev92 commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Denies esbuild's install script, and adds a test that fails when allowScripts falls out of step with the lockfile.

Why

npm 11 skips unapproved install scripts with a warning, not an error. The esbuild approval was pinned to 0.28.1 while the lockfile installed 0.28.2, so its install script was skipped in the Node 24 and 26 jobs for weeks and every job stayed green. The same happens to any pinned approval when the lockfile moves that package, and to any new dependency that brings an install script.

esbuild does not need its install script here. Its platform binary arrives as an optional dependency; the script checks that binary and fetches one only when the dependency is missing. The fixtures use esbuild's JavaScript API, which resolves the binary from the optional dependency at run time.

Changes

  • allowScripts: esbuild is denied by name ("esbuild": false), and a name-only entry cannot fall behind the lockfile. @playwright/browser-chromium@1.63.0 stays approved, since its script downloads the browser the web extension host lane drives. The //allowScripts note is rewritten to match.
  • tests/allow-scripts.test.ts: each pinned approval must match the version the lockfile installs, each entry must name a package the lockfile installs with an install script, and every install script CI would run must be approved or denied. A failure names the fix (npm install-scripts approve <pkg>).

Verification

  • The new suite fails against the manifest and lockfile of 1bf2da4 (esbuild@0.28.1 is pinned but the lockfile installs 0.28.2) and passes here.
  • A moved-back pin, a removed entry, and an entry for a package that is not installed each fail exactly one case.
  • Both fixtures build with esbuild's install script never having run.
  • npm install-scripts ls reports no unreviewed install scripts, and npm install-scripts prune --dry-run finds no unused entries.
  • npm run quality passes.
  • In CI, both host contract lanes bundle their fixtures and pass with esbuild's install script denied, and no install reports scripts outside allowScripts.

🤖 Generated with Claude Code

kkdev92 and others added 2 commits September 29, 2026 14:15
npm 11 skips a dependency's install script unless allowScripts names it, and
reports the skip as a warning. An approval pinned to a version stops matching
as soon as the lockfile moves that package, and a new dependency with an
install script matches nothing, so both cases leave every job green.

The new suite checks that each pinned approval matches the version the
lockfile installs, that every entry names a package the lockfile installs with
an install script, and that every install script CI would run is approved or
denied. Packages the lockfile limits to other operating systems are left out:
they never install on Linux, where CI runs.

Against the manifest and lockfile of 1bf2da4, where the esbuild pin had fallen
behind, the pin check fails on esbuild@0.28.1 while the lockfile installs
0.28.2. A moved-back pin, a removed entry and an entry for a package that is
not installed each fail exactly one case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
esbuild's platform binary arrives as an optional dependency. Its install
script checks that binary and fetches one only when the optional dependency is
missing, and the fixtures use the JavaScript API, which resolves the binary
from that dependency at run time. Both fixtures build with the script never
having run.

A name-only denial also cannot fall behind the lockfile the way a pinned
approval does. That leaves one pinned approval, @playwright/browser-chromium,
whose script downloads the browser the web extension host lane drives. The
//allowScripts note now says so.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kkdev92
kkdev92 merged commit a035506 into main Sep 29, 2026
10 checks passed
@kkdev92
kkdev92 deleted the chore/install-script-review branch September 29, 2026 05:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant