Repository navigation
feat(js-ts-npm): Log npm configuration diagnostics in build and publish jobs - #98
Merged
Merged
Conversation
…sh jobs Add an npm configuration diagnostics step to the JS/TS npm package profile's reusable workflow. The step records node/npm versions, the count of ambient NPM_CONFIG_* variables (names and values are never logged), a redacted `npm config ls` (auth tokens, passwords, and _auth lines are masked defensively since the reusable workflow runs in caller repository contexts), and the provenance/registry key view across all config layers. Motivation: the fourth M1 dogfood (#97) showed that npm trusted publishing auto-enables provenance and silently discards the --provenance-file bundle. Root-cause analysis would have been faster with a captured npm config view from the publish job; the same artifact is generally useful when triaging trusted-publishing and provenance issues in caller runs. Signed-off-by: Yunseo Kim <git@yunseo.kim>
Signed-off-by: Yunseo Kim <git@yunseo.kim>
…tics Extend the npm configuration diagnostics step in the build job: when the selected package resolves to a non-npm package manager via the packageManager field (package directory first, then repository root, matching corepack walk-up), additionally log that manager's configuration — `pnpm config list` (auth settings already hidden by pnpm v11+, redacted again defensively) or `yarn config`. Redaction is unified through a small node-based filter that masks credential-shaped values (_authToken, _password, :_auth, npmAuthToken, npmAuthIdent) in ini, YAML, and single- or multi-line JSON output shapes, plus URL-embedded credentials, while preserving surrounding structure. The publish job step is unchanged: publishing uses npm only and the job has no Corepack shims. Signed-off-by: Yunseo Kim <git@yunseo.kim>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds configuration diagnostics logging to the JS/TS npm package profile's reusable workflow (
.github/workflows/js-ts-npm-package-slsa3.yml).buildandpublishjobs — new step "Log npm configuration diagnostics" recording:NPM_CONFIG_*variables (names and values are never logged);npm config lswith redaction of credential-shaped values;provenance/provenance-file/registry/access/tagkey view across all config layers (npm config ls -l | grep).buildjob additionally: when the selected package resolves to a non-npm package manager via thepackageManagerfield (package directory first, then repository root, matching Corepack walk-up), the step also logs that manager's configuration —pnpm config list(auth settings are already hidden by pnpm v11+; redacted again defensively) oryarn config. The publish job step stays npm-only: publishing uses npm only and the job has no Corepack shims._authToken,_password,:_auth,npmAuthToken, andnpmAuthIdentvalues across ini (key = value), YAML-ish (key: value), and single- or multi-line JSON output shapes, plus URL-embedded credentials (://user:pass@), while preserving surrounding structure. This matters because the reusable workflow executes in caller repository contexts.--provenance-filebundle. Root-cause analysis would have been materially faster with a captured npm config view from the publish job. The same artifact is generally useful when triaging trusted-publishing/provenance and package-manager configuration issues in caller runs.Related Issues
Change Type
Changelog
Changelog update:
[Unreleased]entry added in this PRChecklist
General
type(scope): SummaryProtocol / Compatibility Impact
Testing
Describe test evidence:
actionlintclean (shellcheck SC2016 suppression documented for the intentionally single-quoted node script);prettier --checkclean; redaction filter tested locally against yarn-style (npmAuthToken: "...", nestednpmRegistries), pnpm-style (single-line and pretty JSON with//registry/:_authTokenkeys), npm-ini-style, and credential-bearing proxy URLs — sensitive values masked, surrounding structure preserved;packageManagerfield walk-up (package directory, then repository root) verified locally.Documentation
Rollout / Risk
Reviewer Checklist