Repository navigation
docs: v3.2.0 VSIX provenance, inventory, dependency audit, scans + reproducibility (THQ-132-136) - #518
Conversation
Acquires the four published platform VSIX files from Open VSX (Actions artefacts for the publish run were not retained) and fixes their identity via SHA-256, cross-checked against Open VSX's own published hashes. Feeds the epic transitrix-hq#130 audit opened after the VS Marketplace listing was removed as Malware (transitrix-hq#127). Signed-off-by: transitrix <279946036+transitrix@users.noreply.github.com>
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
Classifies every one of the 517 paths in each of the four platform VSIX (repo source / generated build output / dependency@version), all evidence-based against git-tracked paths, extension:prep's generating scripts, and each node_modules package's own package.json - no stop-and-report trigger, nothing untraced. Separately inventories every binary/machine-generated entry with runtime-required status. Extends the transitrix-hq#132 audit folder per that task's own PR-reuse instruction. Signed-off-by: transitrix <279946036+transitrix@users.noreply.github.com>
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
Reconstructs the 7 direct + 19 transitive runtime dependencies from the exact versions already inventoried in transitrix-hq#133 (read out of the published VSIX itself, not reinstalled). Finding: extension/ is not an npm workspace member and its own build step installs with --no-package-lock in an isolated temp dir, so root package-lock.json never governed these versions - the artefact itself is the only authoritative record, which is what this check uses. All 26 packages queried against OSV.dev: zero vulnerabilities. Registry metadata (publish date, maintainers, signatures/provenance) recorded for each. Signed-off-by: transitrix <279946036+transitrix@users.noreply.github.com>
…rix-hq#134) Confirms the 4 open repo-level Dependabot alerts are all root package-lock.json (tooling) dependencies, none overlapping the 26 packages shipped inside the VSIX. Signed-off-by: transitrix <279946036+transitrix@users.noreply.github.com>
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
1 similar comment
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
Records clean Microsoft Defender verdicts (local, on-demand, fresh signatures) against all four published VSIX and the full unpacked tree covering every binary/non-plaintext component from transitrix-hq#133. A second independent engine is blocked: no scanner API key is available (VirusTotal/MetaDefender-class services all require one) and ClamAV is not installed locally - acquiring either is a new external dependency, not this run's call to make. Issue stays open pending that decision. Signed-off-by: transitrix <279946036+transitrix@users.noreply.github.com>
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
…ix-hq#135) Second independent engine, unblocked by Valerii's VirusTotal API key decision on transitrix-hq#135. All four published VSIX hashes verified clean. Signed-off-by: transitrix <279946036+transitrix@users.noreply.github.com>
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
Rebuild from tag v3.2.0 (win32-x64 target, the only build host available this run) matches the published Open VSX artefact byte-for-byte across all 519 files; the outer .vsix hash differs only by zip-entry timestamps. The other three published platforms are not independently rebuilt here (no matching build host) but path-diff cleanly against the local rebuild and against transitrix-hq#133's existing cross-platform inventory, with every delta explained. Closes the epic (transitrix-hq#130) with finding (a). Signed-off-by: Valerii Korobeinikov <vkgeorgia@icloud.com> Signed-off-by: transitrix <279946036+transitrix@users.noreply.github.com>
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
Summary
.sha256.extension:prepscript), or a dependency at its resolved exact version — evidence-based againstgit ls-tree, the build scripts, and each package's ownpackage.json. No stop-and-report trigger. Separate binary/machine-generated-bundle table with runtime-required status. Cross-platform note: 3 of 4 artefacts are byte-identical except each platform's own native@resvg/resvg-jsbinary;win32-x64additionally carries CRLF line endings in 13 small text/JSON/SVG files (real difference in the published bytes, consistent with a Windows CI checkout).extension/is not an npm workspace member and its build step installs with--no-package-lockin an isolated temp dir, so rootpackage-lock.jsonnever governed these versions — the published artefact itself (already inventoried in feat(cli): add transitrix bin alias, deprecate cervin (P1) #133) is the only authoritative record. All 26 packages queried against OSV.dev: zero vulnerabilities. Registry metadata (publish date, maintainers, signatures/provenance) recorded per package. Cross-checked against the repo's 4 open Dependabot alerts — none overlap the shipped dependency set (they're all root-workspace tooling deps)..vsixand their unpacked binary components. Zero malicious/suspicious verdicts on every artefact, every engine.v3.2.0,win32-x64target (the only build host available). Byte-for-byte content match against the publishedwin32-x64artefact: 519/519 files, zero content-hash mismatches; the outer.vsixhash differs only by zip-entry timestamps (build nondeterminism, not content). The other three published platforms are not independently rebuilt (no matching build host in this run's environment) — path-diffed instead against the local rebuild and against feat(cli): add transitrix bin alias, deprecate cervin (P1) #133's existing cross-platform inventory, with the only delta being each platform's own declared, version-pinned native binary, explained not remediated. Writes the epic's finding.Together these close THQ-130 (provenance and binary-content audit, opened after the VS Marketplace listing was removed as Malware — THQ-127) with finding (a): every file in every published artefact traces to a declared, pinned, published dependency version or to repository source, with hashes. The Marketplace artefacts themselves could not be examined (no retrievable bytes — see #132's amendment); the finding is scoped to the Open VSX artefacts, which is stated explicitly rather than silently substituted.
.vsixbinaries are not committed (.gitignorealready excludes*.vsix); the Open VSX URLs are stable so later tasks can re-fetch identical bytes on demand. The one local.vsixbuild performed for the reproducibility check (THQ-136) was explicitly authorised by Valerii for that single purpose and was never published.Test plan
sha256sumon each downloaded.vsixmatches the corresponding Open VSX.sha256filepackage@versionread from that package's ownpackage.jsonextension/package.jsonv3.2.0(win32-x64) matches the published artefact byte-for-byte on content; every remaining difference (zip timestamps, other-platform native binary, CRLF/LF) is explained.vsixbuild for the reproducibility check