Repository navigation
fix(ci): make npm packages reproducible across Linux runner permissions - #291
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
VPS6 checks out and builds public package files with mode
0600; ordinary Linux builders use0644. npm preserves those permissions, so identical file contents from the same source failed the mandatory preparation/publisher digest guard.Both npm jobs now pack from a private staging copy of the validated production inventory, with fixed
0644/0755modes. The helper follows only the two reviewed workspace links, rejects unsafe paths and other symlinks, and requires the final inventory to match. It leaves source permissions and runner umask unchanged. Hosted publishing, provenance, required artifacts and the exact-byte guard remain required.Validation at
c2a0c3a717781b7ae34b37b2f0177bc0e0fb0d91: all 78 scoped packaging/release tests and 20 manual gates passed, including audit, production policy, docs, source integrity, independent rebuild, installed version/help and stalled-auth recovery. Manual private ATS parity passed 110 Node tests and 16 Python tests with no skips. Both workflow files passed actionlint.The final PR package on VPS3 and the same helper applied to unchanged main package inputs on VPS6 reproduce the same 996-file tarball: SHA-256
a3550c7de43109c12b27fc3dbd5d3933091b58e87ed87cc454e6491305823229. VPS6's source file permissions were unchanged. The five changed files are packaging, workflows and documentation; runtime package bytes are unchanged. The full platform suites were not repeated for this CI-only change. Native Actions remain subject to the account billing/storage and private-repository gates. No package has been published.