build(node): pin npm integrity and Node 22/jsdom 30 compatibility - #896
Draft
seonghobae wants to merge 168 commits into
Draft
seonghobae wants to merge 168 commits into
seonghobae wants to merge 168 commits into
Conversation
Collaborator
Author
|
Exact-current hosted evidence update for
This is real current-head evidence that Corepack accepts the reviewed |
This was referenced Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Canonical Node / npm runtime owner
This Draft owns the Node 22 / jsdom 30 compatibility vertical and the repository-wide npm runtime acquisition/provenance contract. #1176 remains the canonical writer for the inherited Ruff formatting prerequisite; #896 consumes that delta by ancestry rather than reimplementing it.
Exact current identity
develop@314ddeae7b775a4957594b599358c8255617eb2e.c37835f150a01b8fc5745b541e51ef79bce830af.develop.8fe6b6d99c009527ef0bcba419e6f6debdb23c23; the visibletest_supply_chain_policy.pyformatter delta is not build(node): pin npm integrity and Node 22/jsdom 30 compatibility #896 semantic ownership.Runtime / supply-chain contract
>=22.22.2 <23, with an exact-minimum Node 22.22.2 CI lane.10.9.9; executing npm is verified together with bundledtar >=7.5.19before dependency extraction.packageManageris integrity-bound to the reviewed npm 10.9.9 SHA-512 artifact.scripts/checks/activate_pinned_npm_runtime.shis the single workflow-level activation path for direct npm execution.ETIMEDOUT, at most three attempts with 5 s / 10 s backoff.npm ci, tests, build/package/release actions.Current hosted RED → repair
Exact predecessor
6763d9158cf93798f62d8e42c20ac400b7ca0a1dproduced a real hosted CI failure after the runtime path itself succeeded.On
gate / ci / node-minimum-compatibility(macOS), Node 22.22.2 setup, integrity-bound npm 10.9.9 acquisition, bundled tar verification, frozen Node dependencies, Python sync, stable Rust/numeric extension, lint and typecheck all completed. The Python suite then exposed that the helper used Bash 4-only${acquisition_output,,}under hosted macOS/bin/bash, causingbad substitutionbefore trust-first/timeout classification could run. The same exact head on Linux did not have that shell failure and instead exposed two stale source-contract assertions: the Node/jsdom test still expected barenpm@10.9.9, and the resilience structural test still searched source for uppercase"ETIMEDOUT"after the classifier had intentionally moved to lowercase matching.Causal repairs on the same owner lane:
2a080035cb66ea1a5a4e1cf9b3682c1a23e35b29: replace${acquisition_output,,}with portableLC_ALL=C tr '[:upper:]' '[:lower:]'; trust markers still take precedence overetimedout.e3ecc44a873a44588855312ddcf4f96436d0f86b: remove the contradictory bare-version package-manager assertion from the Node/jsdom test. Full version+SHA-512 identity remains owned bytest_npm_package_manager_integrity_pin.py.4974765fd8145eb605637e8a84cf955441b8b3d7: structural regression now requires portable normalization, lowercase matcher source, and absence of Bash-specific${acquisition_output,,}while behavioral fixtures continue to emit uppercaseETIMEDOUT.c37835f150a01b8fc5745b541e51ef79bce830af: code-current TRACEABILITY for the hosted portability RCA and claim boundary.The failed
6763d915...run is predecessor RED evidence only. It proves the exact runtime acquisition path reached npm 10.9.9 successfully on macOS/Linux, but its failing verdict does not transfer to the moved current head.Earlier fail-closed repairs retained
bc26032...→ repair4cee8f5d...: provenance/integrity failure takes precedence over anETIMEDOUTtoken in the same Corepack diagnostic.628aa96b...→2ddd8b15.../ab04754d...: remove weaker workflow-local Corepack activation from release/security paths.df20e638...: discover direct npm execution across repository workflows rather than one install-command spelling.a990e7c7...: remove the legacy inline-activation fallback fromtest_npm_toolchain_contract.py.19ddd51d...→ repairdc726efb...: detect npm behind ordinary shell control syntax (then,do, grouping, negation,exec) without treating harmlessecho npm ...text as a consumer.237ff476...→ repaireee83e3a...: normalize shell escaped-newline token joining before direct-npm admission.Current exact-head evidence
Fresh repository generations now exist for
c37835f150a01b8fc5745b541e51ef79bce830af:SAST Semgrep35660841954: queued;build-baseline35660842172: queued;Security Scan35660842433: queued;sbom35660842213: queued;CodeQL PR35660842048: pending;ci35660842046: queued.Queued/pending is non-passing. The predecessor RED and predecessor native successes do not transfer.
Formal review inventory still contains only two historical GitHub Advanced Security
COMMENTEDsubmissions. Their Scorecard threads refer to the removed standalone workflow and are resolved/outdated. There is no qualifying independent non-author current-headAPPROVED. Keep Draft.Downstream consumer / owner boundary
Score Storage #1241 is downstream evidence, not an npm-runtime source owner. Required order remains:
#896 protected integration → ordinary/non-force #1241 reconciliation → consume the protected helper in
score-storage-native.yml→ fresh exact-head UI execution.#1241 must not vendor this mutable Draft helper. Production separation/model behavior remains Signal/MIR ownership; #896 does not mock/narrow that product path or copy MIR source.
Merge gate
One unchanged final head must obtain terminal-success applicable repository/central CI, native builds, security/SAST/SBOM/supply-chain/CodeQL gates, zero valid unresolved findings, and a qualifying independent non-author current-head approval before ordinary merge.
No self-approval, force-push, destructive rebase, gate weakening, source-neutral freshness commit, blind rerun, bundled/system/latest npm fallback, integrity bypass, predecessor-evidence transfer, filename exception for a new npm consumer, inline activation bypass, shell-control-flow or escaped-newline bypass, timeout-over-provenance precedence, or source-copy repair into downstream consumers.