From 26586b1a6b0d8954332300639f585795dba5fc1c Mon Sep 17 00:00:00 2001 From: Alberto Martinez Date: Sat, 28 Mar 2026 21:45:24 -0700 Subject: [PATCH] security: enforce frozen lockfile during setup bun install with caret ranges (^1.58.2) resolves to latest compatible versions at install time. A compromised npm publish of playwright or puppeteer-core would get code execution on every setup run. Using --frozen-lockfile ensures the resolved versions in bun.lock are used exactly, preventing dependency confusion attacks. The fallback in the .agents/ generation block (line 199) already uses --frozen-lockfile. This makes the main build block consistent. Made-with: Cursor --- setup | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/setup b/setup index e66a6df0f0..1424a8e02d 100755 --- a/setup +++ b/setup @@ -170,7 +170,7 @@ if [ "$NEEDS_BUILD" -eq 1 ]; then echo "Building browse binary..." ( cd "$SOURCE_GSTACK_DIR" - bun install + bun install --frozen-lockfile bun run build ) # Safety net: write .version if build script didn't (e.g., git not available during build)