Repository navigation
fix(ng-dev/release): harden release publish npm config isolation, tag verification, and child process sanitization - #4028
Open
josephperrott wants to merge 4 commits into
Conversation
…level .npmrc Ensure npm publish, checkVersionExists, and deprecate commands executed during CI release publishing run with their working directory set to the isolated temporary directory containing the generated Wombat .npmrc, preventing any project-level .npmrc in the workspace root from taking precedence over NPM_CONFIG_USERCONFIG.
There was a problem hiding this comment.
Code Review
This pull request enhances the release publishing workflow by verifying that existing Git tags or releases match the expected SHA on HTTP 422 errors, isolating NPM commands within a temporary directory, and adding safety flags to pnpm install. It also ensures that rejected log outputs are sanitized in silent mode to prevent token leaks. Feedback on these changes suggests resolving the commit SHA for annotated tags during verification to prevent false mismatches, and rejecting failed child processes with a proper Error object instead of undefined to avoid anti-patterns.
…TP 422 during publish When tag or GitHub release creation returns HTTP 422 (already exists), query the existing tag reference via git.getRef and verify its commit SHA matches expectedSha before marking the item as SKIPPED. If the SHA does not match or the verification fails, record a FAILED status and abort package publishing.
…ng release pnpm install Pass --ignore-scripts and --ignore-pnpmfile to pnpm install in ExternalCommands.invokePnpmInstall so lifecycle hooks and repository .pnpmfile.cjs scripts cannot execute while caretaker release credentials are active.
…silent mode Ensure that when a child process executed with mode: 'silent' exits with a non-zero status code, the rejected logOutput string is passed through sanitize() to redact any embedded URL credentials.
josephperrott
force-pushed
the
fix/release-publish-hardening
branch
from
October 9, 2026 20:32
f21c965 to
81ad8b0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
github-actions/release/publish,ng-dev/release/versioning): ExecuteNpmCommand.checkVersionExists,NpmCommand.publish, andNpmCommand.deprecateduring CI release publishing withcwdset to the isolated temporary directory containing the Wombat.npmrc, and resolve tarball paths so any repository-level.npmrcin the workspace cannot overrideNPM_CONFIG_USERCONFIG.github-actions/release/publish): Whengit.createReforrepos.createReleasereturns HTTP 422 (already exists), fetch the existing tag reference viagit.getRefand verify its commit SHA matchesexpectedShabefore marking itSKIPPED. If the SHA mismatches or verification fails, mark itFAILEDand skip package publishing.pnpm installduring release preparation (ng-dev/release/publish): Pass--ignore-scriptsand--ignore-pnpmfileinExternalCommands.invokePnpmInstallso lifecycle scripts and.pnpmfile.cjshooks cannot execute while release credentials are active.logOutputin silent mode (ng-dev/utils): PasslogOutputthroughsanitize()when rejecting a failed child process inmode: "silent"so URL credentials are redacted consistently.