Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
69 changes: 69 additions & 0 deletions .github/workflows/js-ts-npm-package-slsa3.yml
Original file line number Diff line number Diff line change
Expand Up @@ -132,6 +132,66 @@ jobs:
- name: Enable Corepack
run: corepack enable

- name: Log npm configuration diagnostics
env:
PACKAGE_DIRECTORY: ${{ inputs.package-directory }}
REPOSITORY_ROOT: ${{ github.workspace }}/source
run: |
redact() {
# shellcheck disable=SC2016 # node script is intentionally single-quoted.
node -e '
const sensitive = /(_authtoken|_password|:_auth|npmauthtoken|npmauthident)/i;
let input = "";
process.stdin.on("data", (chunk) => (input += chunk)).on("end", () => {
const out = input.split("\n").map((line) => {
if (sensitive.test(line)) {
if (line.includes("{") || line.trimStart().startsWith(String.fromCharCode(34))) {
line = line.replace(
/("[^"]*(?:_authToken|_password|_auth|npmAuthToken|npmAuthIdent)[^"]*"\s*:\s*")[^"]*(")/gi,
"$1<redacted>$2",
);
} else {
const idx = line.search(/[=:]/);
if (idx >= 0) line = line.slice(0, idx + 1) + " <redacted>";
}
}
return line.replace(/(:\/\/)[^/@\s]+:[^/@\s]+@/g, "$1<redacted>@");
});
process.stdout.write(out.join("\n"));
});
'
}
echo "node: $(node --version), npm: $(npm --version)"
echo "ambient NPM_CONFIG_* variables: $(env | grep -c '^NPM_CONFIG_' || true)"
npm config ls 2>&1 | redact
echo "--- provenance/registry keys across all config layers ---"
npm config ls -l 2>&1 | grep -iE '^(provenance|provenance-file|registry|access|tag)\b' || true
echo "--- selected package manager (packageManager field, package then root) ---"
pm_spec=$(node -e '
const fs = require("fs");
for (const candidate of [process.argv[1], process.argv[2]]) {
try {
const pm = JSON.parse(fs.readFileSync(candidate, "utf8")).packageManager;
if (typeof pm === "string" && pm.length > 0) { console.log(pm); process.exit(0); }
} catch {}
}
' "$REPOSITORY_ROOT/$PACKAGE_DIRECTORY/package.json" "$REPOSITORY_ROOT/package.json")
pm_name="${pm_spec%%@*}"
echo "packageManager: ${pm_spec:-<none declared; npm default>}"
case "$pm_name" in
pnpm)
echo "--- pnpm config list (auth hidden by pnpm v11+; redacted again defensively) ---"
(cd "$REPOSITORY_ROOT/$PACKAGE_DIRECTORY" && pnpm config list 2>&1) | redact || true
;;
yarn)
echo "--- yarn config (redacted) ---"
(cd "$REPOSITORY_ROOT/$PACKAGE_DIRECTORY" && yarn config 2>&1) | redact || true
;;
*)
echo "package manager is npm (or unspecified); npm configuration shown above"
;;
esac

- name: Create trusted output directory
env:
OUTPUT_DIRECTORY: ${{ runner.temp }}/windlass-build-output
Expand Down Expand Up @@ -353,6 +413,15 @@ jobs:
with:
node-version: "24"

- name: Log npm configuration diagnostics
if: needs.build.result == 'success' && needs.provenance-sign.result == 'success'
run: |
echo "node: $(node --version), npm: $(npm --version)"
echo "ambient NPM_CONFIG_* variables: $(env | grep -c '^NPM_CONFIG_' || true)"
npm config ls 2>&1 | sed -E '/_authToken|_password|:_auth/Is/=.*/=<redacted>/'
echo "--- provenance/registry keys across all config layers ---"
npm config ls -l 2>&1 | grep -iE '^(provenance|provenance-file|registry|access|tag)\b' || true

- name: Download package tarball handoff
if: needs.build.result == 'success' && needs.provenance-sign.result == 'success'
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,12 @@ Human Era five-digit years (e.g., `## [0.1.0] - 12026-06-13`).

### Added

- Added npm configuration diagnostics logging to the JS/TS npm reusable workflow's build and publish
jobs: node/npm versions, ambient `NPM_CONFIG_*` variable count, redacted `npm config ls` output,
and the provenance/registry key view across all config layers, to aid trusted-publishing and
provenance triage in caller runs. The build job additionally logs the selected non-npm package
manager's configuration (pnpm `config list` or `yarn config`, resolved from the `packageManager`
field) with the same redaction of credential-shaped values.
- Added a Go testing and fuzzing guide (`docs/testing-guide.md`) defining test organization,
security-negative testing, quality gates, and the fuzzing policy for trust-boundary parsers.
- Added property-based fuzz targets for all trust-boundary parsers and validators (attestation
Expand Down