Skip to content

feat(js-ts-npm): Log npm configuration diagnostics in build and publish jobs - #98

Merged
yunseo-kim merged 3 commits into
mainfrom
feat/npm-config-diagnostics
Aug 16, 2026
Merged

yunseo-kim merged 3 commits into
mainfrom
feat/npm-config-diagnostics

Conversation

@yunseo-kim

@yunseo-kim yunseo-kim commented Aug 16, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds configuration diagnostics logging to the JS/TS npm package profile's reusable workflow (.github/workflows/js-ts-npm-package-slsa3.yml).

  • What changed?
    • build and publish jobs — new step "Log npm configuration diagnostics" recording:
      1. node/npm versions;
      2. the count of ambient NPM_CONFIG_* variables (names and values are never logged);
      3. npm config ls with redaction of credential-shaped values;
      4. the provenance/provenance-file/registry/access/tag key view across all config layers (npm config ls -l | grep).
    • build job additionally: when the selected package resolves to a non-npm package manager via the packageManager field (package directory first, then repository root, matching Corepack walk-up), the step also logs that manager's configuration — pnpm config list (auth settings are already hidden by pnpm v11+; redacted again defensively) or yarn config. The publish job step stays npm-only: publishing uses npm only and the job has no Corepack shims.
    • Redaction is unified through a small node-based filter (node runs in both jobs; avoids BSD/GNU sed dialect differences) that masks _authToken, _password, :_auth, npmAuthToken, and npmAuthIdent values across ini (key = value), YAML-ish (key: value), and single- or multi-line JSON output shapes, plus URL-embedded credentials (://user:pass@), while preserving surrounding structure. This matters because the reusable workflow executes in caller repository contexts.
  • Why is this needed?
  • Security posture: the publish-job step runs before the mutation (no exchanged token exists yet), logs no env names/values, and redacts credential-shaped config lines. No behavior change to build/sign/publish paths.
  • How to test: actionlint and prettier pass; the redaction filter was exercised locally against five output-format classes (yarn YAML-ish, pnpm JSON single-line and pretty-printed, npm ini, passthrough, proxy URLs with embedded credentials); the packageManager walk-up detection was exercised locally against package-dir-then-root candidates. First live output will appear in the next caller run after the caller pin is bumped.

Related Issues

Change Type

  • CI / workflow

Changelog

  • Category: Added
  • User-facing note: The JS/TS npm reusable workflow now logs redacted npm configuration diagnostics in the build and publish jobs, and additionally the selected pnpm/Yarn package manager's configuration in the build job, aiding trusted-publishing, provenance, and package-manager triage in caller runs.

Changelog update:

  • [Unreleased] entry added in this PR

Checklist

General

  • PR title follows Conventional Commits format: type(scope): Summary
  • This PR does not expose backend/internal implementation details in a public repo.
  • No secrets, tokens, keys, or private endpoints are included.
  • Changes stay within this repository's intended scope.

Protocol / Compatibility Impact

  • No protocol/spec impact (diagnostic logging only; no behavior or contract change)

Testing

  • Lint and format pass
  • Manual verification performed

Describe test evidence: actionlint clean (shellcheck SC2016 suppression documented for the intentionally single-quoted node script); prettier --check clean; redaction filter tested locally against yarn-style (npmAuthToken: "...", nested npmRegistries), pnpm-style (single-line and pretty JSON with //registry/:_authToken keys), npm-ini-style, and credential-bearing proxy URLs — sensitive values masked, surrounding structure preserved; packageManager field walk-up (package directory, then repository root) verified locally.

Documentation

  • No docs needed (diagnostic logging; no contract surface change)
  • Changelog decision completed above

Rollout / Risk

  • Risk level: Low (additive log step; no behavior change; redaction guards caller-context secrets)
  • Rollback plan: revert this branch.

Reviewer Checklist

  • Scope is clear and minimal
  • Security and boundary checks passed
  • Tests and docs are sufficient
  • Compatibility impact is correctly handled

…sh jobs

Add an npm configuration diagnostics step to the JS/TS npm package
profile's reusable workflow. The step records node/npm versions, the
count of ambient NPM_CONFIG_* variables (names and values are never
logged), a redacted `npm config ls` (auth tokens, passwords, and _auth
lines are masked defensively since the reusable workflow runs in caller
repository contexts), and the provenance/registry key view across all
config layers.

Motivation: the fourth M1 dogfood (#97) showed
that npm trusted publishing auto-enables provenance and silently
discards the --provenance-file bundle. Root-cause analysis would have
been faster with a captured npm config view from the publish job; the
same artifact is generally useful when triaging trusted-publishing and
provenance issues in caller runs.

Signed-off-by: Yunseo Kim <git@yunseo.kim>
Signed-off-by: Yunseo Kim <git@yunseo.kim>
…tics

Extend the npm configuration diagnostics step in the build job: when the
selected package resolves to a non-npm package manager via the
packageManager field (package directory first, then repository root,
matching corepack walk-up), additionally log that manager's
configuration — `pnpm config list` (auth settings already hidden by
pnpm v11+, redacted again defensively) or `yarn config`.

Redaction is unified through a small node-based filter that masks
credential-shaped values (_authToken, _password, :_auth, npmAuthToken,
npmAuthIdent) in ini, YAML, and single- or multi-line JSON output
shapes, plus URL-embedded credentials, while preserving surrounding
structure. The publish job step is unchanged: publishing uses npm only
and the job has no Corepack shims.

Signed-off-by: Yunseo Kim <git@yunseo.kim>
@yunseo-kim
yunseo-kim merged commit a91def7 into main Aug 16, 2026
87 of 88 checks passed
@yunseo-kim
yunseo-kim deleted the feat/npm-config-diagnostics branch August 16, 2026 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

npm trusted publishing auto-enables provenance and discards the --provenance-file bundle (dogfood 4 read-back failure)

1 participant