mirror of
https://github.com/openprose/prose.git
synced 2026-09-19 05:55:05 +08:00
f7fa6770c4
Dependency installs and CI jobs both executed code this repo never reviewed. This closes those paths without changing what anything resolves to. pnpm 9 ran every dependency's install lifecycle script and had no allow-list model, so CI executed install hooks from the whole tree on every PR. pnpm 10.34.5 blocks them by default and carries the fix for the fail-open integrity check in CVE-2026-50021. minimumReleaseAge holds freshly published versions out of resolution for 48 hours, the window in which a registry compromise is typically caught and yanked. The two `*` peer ranges in reactor-cli were the only place the workspace opted out of range discipline: any future major satisfied them, including a hijacked one. Both now carry carets on the versions already resolved, and the README install lines are pinned to match, since a 0.x caret does not cross the minor line. Third-party actions take the commit SHA their movable tags resolved to, with a monthly grouped Dependabot entry so those pins do not go stale. GitHub-maintained actions stay on tags as a stated trust decision rather than a claim that pinning them would buy nothing. The benchmark jobs needed the most work, since they run an external repository's code with five LLM provider keys in scope. Dispatch inputs now travel through the step environment as quoted variables instead of being interpolated into shell. The pi version is hardcoded rather than dispatchable: npm accepts package sources after the `@` — an alias, a repository, a tarball URL — so an input in that position chose a package rather than a version. The remaining ref override is documented as an operator escape hatch whose clone target is fixed. The publish job holds a credential that can publish under our name and installed npm at latest before using it. It now pins an exact version above the floor OIDC trusted publishing requires, and fails at that step if the pin does not take. CI also fails on a tampered or unsigned tarball now, checked per publishable package rather than once at the root where npm would only see dev tooling. The advisory audit runs alongside it as a signal, not a gate. Nothing re-resolves: no version or integrity line in the lockfile moves.