mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
* fix(build): spawn npx.cmd through a shell in the electron better-sqlite3 rebuild Node's CVE-2024-27980 hardening makes spawnSync of .cmd/.bat shims fail with status null unless shell:true — the v3.8.47 tag build died on the Windows job with 'better-sqlite3 rebuild against electron 43.1.0 failed (exit null)'. Extracted the spawn plan into electronRebuildPlan.mjs (pure, import-safe) with a regression test; args are fixed literals, no untrusted input reaches the shell. * fix(build): ship head-response-guard.cjs in the npm tarball (#7065) The prepublish prune allowlist (pack-artifact-policy.ts) lacked head-response-guard.cjs, so assembleStandalone copied it and the prune deleted it — every boot of the published 3.8.47 crashed with ERR_MODULE_NOT_FOUND (3rd occurrence of this class; tls-options/3.8.41). Also added to PACK_ARTIFACT_REQUIRED_PATHS so check:pack-artifact fails loudly, plus a closure test that derives every server-ws.mjs sibling import and asserts both lists cover it. * fix(ci): zero the Sonar quality-gate findings on new code - ci.yml sonarqube job: download the coverage artifact into coverage/ so lcov.info lands where sonar.javascript.lcov.reportPaths points — the upload strips the common coverage/ prefix, so 'path: .' left new-code coverage at 0% on every scan - kiro auto-import: await the async isCloudEnabled() gate (S6544 — a bare truthiness check on the Promise made syncToCloud run even with cloud sync disabled) - stream.ts: real JSON fallback in the reasoning-split clone (S3923 — both ternary branches called structuredClone, the promised fallback was dead) - codex executor: handle the async reader.cancel() rejection (S4822) - deterministic localeCompare sorts (S2871 x2) - classify-pr-changes.mjs: confine the argv list file to the workspace (jssecurity:S8707 path-traversal guard) + behavioral tests - Dockerfile: rebuild better-sqlite3 with npm's bundled node-gyp instead of npx --yes (docker:S6505 — no on-demand registry install) * chore(ci): make the Sonar quality gate informational (wait=false) The org's SonarCloud FREE plan cannot associate a custom quality gate — only the built-in Sonar way (80% new coverage) applies, which no full-cycle release PR can realistically meet. The scan still uploads (dashboard, PR decoration); the CI job just no longer fails on the gate. A tuned 'OmniRoute way' gate (coverage >=60, duplication <=5) is already configured in the org for the day the plan is upgraded — re-enable wait=true then. * chore(release): v3.8.48 hotfix bump + changelog (npm 3.8.47 unbootable, #7065) * test: align pack-artifact + dockerfile guards to the corrected contracts pack-artifact-policy.test.ts encoded the pre-#7065 REQUIRED list (without head-response-guard.cjs) and dockerfile-better-sqlite3-node-gyp-6700.test.ts asserted the npx invocation the Sonar fix replaced with npm's bundled node-gyp — both now assert the corrected behavior.
126 lines
4.3 KiB
TypeScript
126 lines
4.3 KiB
TypeScript
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
import {
|
|
APP_STAGING_ALLOWED_EXACT_PATHS,
|
|
APP_STAGING_ALLOWED_PATH_PREFIXES,
|
|
PACK_ARTIFACT_ALLOWED_EXACT_PATHS,
|
|
PACK_ARTIFACT_ALLOWED_PATH_PREFIXES,
|
|
PACK_ARTIFACT_REQUIRED_PATHS,
|
|
findMissingArtifactPaths,
|
|
findUnexpectedArtifactPaths,
|
|
normalizeArtifactPath,
|
|
} from "../../scripts/build/pack-artifact-policy.ts";
|
|
|
|
test("normalizeArtifactPath normalizes slashes and leading relative markers", () => {
|
|
assert.equal(
|
|
normalizeArtifactPath("./app\\scripts\\ad-hoc\\test.js"),
|
|
"app/scripts/ad-hoc/test.js"
|
|
);
|
|
});
|
|
|
|
test("findUnexpectedArtifactPaths flags staged app files outside the allowlist", () => {
|
|
const unexpectedPaths = findUnexpectedArtifactPaths(
|
|
[
|
|
"open-sse/services/compression/engines/rtk/filters/generic-output.json",
|
|
"open-sse/services/compression/rules/en/filler.json",
|
|
"package-lock.json",
|
|
"scripts/dev/sync-env.mjs",
|
|
"server.js",
|
|
],
|
|
{
|
|
exactPaths: APP_STAGING_ALLOWED_EXACT_PATHS,
|
|
prefixPaths: APP_STAGING_ALLOWED_PATH_PREFIXES,
|
|
}
|
|
);
|
|
|
|
assert.deepEqual(unexpectedPaths, ["package-lock.json"]);
|
|
});
|
|
|
|
test("findUnexpectedArtifactPaths flags app pack files outside the allowlist", () => {
|
|
const unexpectedPaths = findUnexpectedArtifactPaths(
|
|
[
|
|
"dist/open-sse/services/compression/engines/rtk/filters/generic-output.json",
|
|
"dist/open-sse/services/compression/rules/en/filler.json",
|
|
"dist/server.js",
|
|
"dist/scripts/dev/sync-env.mjs",
|
|
"dist/scripts/build/prepublish.mjs",
|
|
"docs/extra.md",
|
|
],
|
|
{
|
|
exactPaths: PACK_ARTIFACT_ALLOWED_EXACT_PATHS,
|
|
prefixPaths: PACK_ARTIFACT_ALLOWED_PATH_PREFIXES,
|
|
}
|
|
);
|
|
|
|
assert.deepEqual(unexpectedPaths, ["dist/scripts/build/prepublish.mjs", "docs/extra.md"]);
|
|
});
|
|
|
|
test("webdav-handler.mjs is allowed in staging dist/ (server-ws.mjs dependency, missed in 3.8.22 build)", () => {
|
|
const unexpectedPaths = findUnexpectedArtifactPaths(["webdav-handler.mjs"], {
|
|
exactPaths: APP_STAGING_ALLOWED_EXACT_PATHS,
|
|
prefixPaths: APP_STAGING_ALLOWED_PATH_PREFIXES,
|
|
});
|
|
assert.deepEqual(unexpectedPaths, []);
|
|
});
|
|
|
|
test("tls-options.mjs is allowed in staging dist/ (server-ws.mjs dependency, missed in 3.8.41 build — #5452)", () => {
|
|
const unexpectedPaths = findUnexpectedArtifactPaths(["tls-options.mjs"], {
|
|
exactPaths: APP_STAGING_ALLOWED_EXACT_PATHS,
|
|
prefixPaths: APP_STAGING_ALLOWED_PATH_PREFIXES,
|
|
});
|
|
assert.deepEqual(unexpectedPaths, []);
|
|
});
|
|
|
|
test("dist/tls-options.mjs is a required tarball path (regression guard for #5452)", () => {
|
|
const missingPaths = findMissingArtifactPaths([], PACK_ARTIFACT_REQUIRED_PATHS);
|
|
assert.ok(
|
|
missingPaths.includes("dist/tls-options.mjs"),
|
|
"dist/tls-options.mjs must be enforced by the pack-artifact gate"
|
|
);
|
|
});
|
|
|
|
test("setupPolyfill.ts is allowed in the tarball (bin/omniroute.mjs imports it at startup)", () => {
|
|
const unexpectedPaths = findUnexpectedArtifactPaths(["open-sse/utils/setupPolyfill.ts"], {
|
|
exactPaths: PACK_ARTIFACT_ALLOWED_EXACT_PATHS,
|
|
prefixPaths: PACK_ARTIFACT_ALLOWED_PATH_PREFIXES,
|
|
});
|
|
|
|
assert.deepEqual(unexpectedPaths, []);
|
|
});
|
|
|
|
test("findMissingArtifactPaths flags missing root runtime files in the tarball", () => {
|
|
const missingPaths = findMissingArtifactPaths(
|
|
[
|
|
"dist/server.js",
|
|
"bin/omniroute.mjs",
|
|
"package.json",
|
|
"scripts/build/postinstall.mjs",
|
|
"scripts/build/postinstallSupport.mjs",
|
|
],
|
|
PACK_ARTIFACT_REQUIRED_PATHS
|
|
);
|
|
|
|
// findMissingArtifactPaths returns the missing required paths sorted
|
|
// alphabetically (bin/ < dist/ < scripts/ < src/), minus the paths present
|
|
// above (dist/server.js, bin/omniroute.mjs, package.json, the postinstall scripts).
|
|
assert.deepEqual(missingPaths, [
|
|
"bin/cli/program.mjs",
|
|
"bin/mcp-server.mjs",
|
|
"bin/nodeRuntimeSupport.mjs",
|
|
"dist/head-response-guard.cjs",
|
|
"dist/http-method-guard.cjs",
|
|
"dist/open-sse/services/compression/engines/rtk/filters/generic-output.json",
|
|
"dist/open-sse/services/compression/rules/en/filler.json",
|
|
"dist/peer-stamp.mjs",
|
|
"dist/responses-ws-proxy.mjs",
|
|
"dist/server-ws.mjs",
|
|
"dist/tls-options.mjs",
|
|
"dist/webdav-handler.mjs",
|
|
"scripts/build/colocateOptionals.mjs",
|
|
"scripts/build/native-binary-compat.mjs",
|
|
"scripts/build/runtime-env.mjs",
|
|
"src/shared/utils/nodeRuntimeSupport.ts",
|
|
]);
|
|
});
|