Skip to content

fix(ng-dev/release): harden release publish npm config isolation, tag verification, and child process sanitization - #4028

Open
josephperrott wants to merge 4 commits into
angular:mainfrom
josephperrott:fix/release-publish-hardening
Open

josephperrott wants to merge 4 commits into
angular:mainfrom
josephperrott:fix/release-publish-hardening

Conversation

@josephperrott

Copy link
Copy Markdown
Member

Summary

  • Isolate npm publish working directory (github-actions/release/publish, ng-dev/release/versioning): Execute NpmCommand.checkVersionExists, NpmCommand.publish, and NpmCommand.deprecate during CI release publishing with cwd set to the isolated temporary directory containing the Wombat .npmrc, and resolve tarball paths so any repository-level .npmrc in the workspace cannot override NPM_CONFIG_USERCONFIG.
  • Verify existing tag & release commit SHA on HTTP 422 (github-actions/release/publish): When git.createRef or repos.createRelease returns HTTP 422 (already exists), fetch the existing tag reference via git.getRef and verify its commit SHA matches expectedSha before marking it SKIPPED. If the SHA mismatches or verification fails, mark it FAILED and skip package publishing.
  • Harden pnpm install during release preparation (ng-dev/release/publish): Pass --ignore-scripts and --ignore-pnpmfile in ExternalCommands.invokePnpmInstall so lifecycle scripts and .pnpmfile.cjs hooks cannot execute while release credentials are active.
  • Sanitize rejected logOutput in silent mode (ng-dev/utils): Pass logOutput through sanitize() when rejecting a failed child process in mode: "silent" so URL credentials are redacted consistently.

…level .npmrc

Ensure npm publish, checkVersionExists, and deprecate commands executed during CI release publishing run with their working directory set to the isolated temporary directory containing the generated Wombat .npmrc, preventing any project-level .npmrc in the workspace root from taking precedence over NPM_CONFIG_USERCONFIG.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request enhances the release publishing workflow by verifying that existing Git tags or releases match the expected SHA on HTTP 422 errors, isolating NPM commands within a temporary directory, and adding safety flags to pnpm install. It also ensures that rejected log outputs are sanitized in silent mode to prevent token leaks. Feedback on these changes suggests resolving the commit SHA for annotated tags during verification to prevent false mismatches, and rejecting failed child processes with a proper Error object instead of undefined to avoid anti-patterns.

Comment thread github-actions/release/publish/lib/publish-ci.ts Outdated
Comment thread ng-dev/utils/child-process.ts
…TP 422 during publish

When tag or GitHub release creation returns HTTP 422 (already exists), query the existing tag reference via git.getRef and verify its commit SHA matches expectedSha before marking the item as SKIPPED. If the SHA does not match or the verification fails, record a FAILED status and abort package publishing.
…ng release pnpm install

Pass --ignore-scripts and --ignore-pnpmfile to pnpm install in ExternalCommands.invokePnpmInstall so lifecycle hooks and repository .pnpmfile.cjs scripts cannot execute while caretaker release credentials are active.
…silent mode

Ensure that when a child process executed with mode: 'silent' exits with a non-zero status code, the rejected logOutput string is passed through sanitize() to redact any embedded URL credentials.
@josephperrott
josephperrott force-pushed the fix/release-publish-hardening branch from f21c965 to 81ad8b0 Compare October 9, 2026 20:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant