ci(sdk): fail the export snapshot on secret-bearing symbols (#412) - #467
Open
Hustler490 wants to merge 1 commit into
Open
Hustler490 wants to merge 1 commit into
Hustler490 wants to merge 1 commit into
Conversation
…und-commit-window
|
@Hustler490 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Hustler490
force-pushed
the
ci/sdk-export-secret-guard
branch
from
October 4, 2026 15:58
823de2c to
d37f923
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #412.
What
Hardens the SDK public-API snapshot test so an accidentally-exported secret-bearing symbol fails CI.
packages/sdk/src/index.tsinstead of importing the SDK, so it never constructs a network client (acceptance Add bounded retry and backoff policies to keeper RPC and Drand operations #4) and does not depend on the runtime module graph.EXPECTED_EXPORTSsnapshot fails, and any snapshot entry no longer exported fails./(secret|seed|keypair|privatekey|privkey|mnemonic|rawkey|...)/ifails, even if it has been added to the snapshot - unless the name is on the explicit, reviewedALLOWLISTED_SECRET_SYMBOLSset (empty today). This is the "fail even if added to the snapshot without the allowlist" criterion.ROUND_PHASES,ROUND_PHASE_LABELS,isRoundPhase,roundPhaseLabel,ROUND_EVENT_*,expectedRoundEventSequence,diffContractErrorMapping,validatePasskeySession- were missing from the stale snapshot).Focused base fixes (to make the declared surface match the snapshot)
SubRosaPaginationErrorclass toerrors.ts(used byclient.tsbut previously undefined).networkPassphrasesMatch+SubRosaNetworkPassphraseMismatchError(fromnetwork.ts) andparseMicroStroops(frommainnet-readiness.ts) fromindex.ts, which the committed snapshot already expected.Tests
node --import tsx --test src/public-api-snapshot.test.ts-> 12 passed (snapshot match, no secret-bearing value/type, extra/missing guards, value/type separation, source-level secret-type detection, allowlist).Honest note on the base
This is a focused change per maintainer direction.
mainis independently broken:packages/sdk/src/errors.tsis missing theROUND_CONTRACT_ERRORSmapping (getRoundContractError/isRoundContractErrorRetryable/diffContractErrorMapping/ROUND_CONTRACT_ERRORS_BY_NAME) thatindex.tsre-exports anderrors.test.tsimports - so importing the SDK (andsdk:typecheck) still fails for reasons unrelated to this PR. The snapshot test no longer imports the SDK, so it runs and passes regardless. I can reconstruct the error mapping in a follow-up if you'd like #412 to also unblock the runtime import.