Skip to content

fix(release): fully sanitize npm lookup diagnostics - #3321

Merged
kojiwakayama merged 4 commits into
mainfrom
fix/npm-release-diagnostic-redaction
Aug 3, 2026
Merged

kojiwakayama merged 4 commits into
mainfrom
fix/npm-release-diagnostic-redaction

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Summary

  • redact complete Bearer credentials in npm registry lookup failures
  • redact POSIX, Windows-drive, and UNC absolute paths without corrupting registry URLs
  • migrate the release-script regression suite to the required BDD test API
  • keep the scripts lockfile frozen-compatible for the BDD import

Verification

  • bash -n scripts/ci/publish-npm-packages.sh
  • focused test: 1 group / 5 steps passed with --frozen
  • deno check --config=scripts/test.deno.json --frozen scripts/ci/publish-npm-packages.test.ts
  • deno task verify:quick

Follow-up to #3317, which merged while its two review threads were being addressed.

Copilot AI review requested due to automatic review settings August 3, 2026 09:27
@kojiwakayama
kojiwakayama requested a review from kwakayama as a code owner August 3, 2026 09:27
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@kojiwakayama, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 936a1da0-c685-4f56-8bff-7e30a3034225

📥 Commits

Reviewing files that changed from the base of the PR and between d63ea1b and 993a3ca.

⛔ Files ignored due to path filters (1)
  • scripts/deno.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • scripts/ci/publish-npm-packages.sh
  • scripts/ci/publish-npm-packages.test.ts

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the release preflight diagnostics in scripts/ci/publish-npm-packages.sh by further sanitizing npm registry lookup failures (credentials and absolute paths), and updates the associated regression tests to the project’s BDD test API with a scripts lockfile update to keep --frozen compatibility.

Changes:

  • Expand npm lookup stderr sanitization to redact full Bearer credentials and broader absolute path formats (POSIX, Windows drive, UNC) while avoiding registry URL corruption.
  • Migrate the publish preflight regression suite to #veryfront/testing/bdd.ts and add assertions for the new sanitization behavior.
  • Update scripts/deno.lock to include the additional dependency required by the BDD import graph under --frozen.

Verification:

  • Not run as part of this review. PR description reports:
    • bash -n scripts/ci/publish-npm-packages.sh
    • focused test: 1 group / 5 steps passed with --frozen
    • deno check --config=scripts/test.deno.json --frozen scripts/ci/publish-npm-packages.test.ts
    • deno task verify:quick

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated 1 comment.

File Description
scripts/ci/publish-npm-packages.sh Strengthens npm lookup stderr sanitization for release preflight failures.
scripts/ci/publish-npm-packages.test.ts Converts to BDD tests and adds coverage for new sanitization expectations.
scripts/deno.lock Adds a missing frozen-lock entry needed by the updated test import graph.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread scripts/ci/publish-npm-packages.sh Outdated
Absolute-path redaction previously consumed closing double quotes because each path pattern matched every non-whitespace character. The sanitizer now stops at quote delimiters and regression coverage exercises quoted POSIX, Windows-drive, and UNC paths.

Constraint: Registry diagnostics must redact machine-local paths without corrupting the surrounding npm message.
Rejected: Rebalance quotes after sanitization | delimiter-aware matching is smaller and preserves the original syntax.
Confidence: high
Scope-risk: narrow
Reversibility: clean
Tested: focused release-script BDD suite, format, lint, typecheck, Bash syntax, and git diff check
Not-tested: full repository suite
Copilot AI review requested due to automatic review settings August 3, 2026 09:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 3 changed files in this pull request and generated no new comments.

npm failures can report absolute paths inside quotes, brackets, and file URIs. Sanitize these structured forms before the existing unquoted fallback so complete paths are removed without consuming their delimiters or altering registry URLs.

Constraint: The release helper must remain portable across the Bash and sed implementations used locally and in GitHub Actions.
Rejected: Replace sed with a new parser dependency | unnecessary dependency and release-path complexity.
Confidence: high
Scope-risk: narrow
Reversibility: clean
Directive: Keep structured path rules ahead of the unquoted fallback so paths containing spaces are redacted as one value.
Tested: Focused 5-step BDD suite, bash -n, Deno fmt/lint/check, deno task verify:quick, git diff --check.
Not-tested: Live npm diagnostic variants outside the covered POSIX, Windows, UNC, quoted, bracketed, and file URI forms.
Copilot AI review requested due to automatic review settings August 3, 2026 10:01
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Independent review found that npm diagnostics could still leak local paths when values used single quotes, brackets, spaces inside quotes, or file:// URIs. Fixed in 37353de6c.

Regression coverage now verifies POSIX and Windows-style paths, preserved closing quotes and brackets, file://<path> redaction, existing bearer-token redaction, and an unchanged npm registry URL.

Verification passed: focused BDD (5/5 steps), bash -n, Deno fmt/lint/check, deno task verify:quick, git diff --check, and the pre-push suite (3,718 tests, 26,693 steps). I have not queued or merged this PR.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 3 changed files in this pull request and generated no new comments.

Npm registry diagnostics can wrap fallback token and path values in quotes, parentheses, or comma-delimited text. The sanitizer now stops fallback matches before those delimiters while preserving the existing redaction output shape for credentials and local paths.

Constraint: Scoped to PR #3321 npm release diagnostic sanitizer follow-up.

Rejected: Rewrite sanitizer away from sed | too broad for a release-script follow-up.

Confidence: high

Scope-risk: narrow

Directive: Keep fallback redaction patterns delimiter-aware when adding new token or path forms.

Tested: Focused regression showed RED before the sanitizer change, then passed: deno test --config=scripts/test.deno.json --frozen --allow-all scripts/ci/publish-npm-packages.test.ts.

Tested: bash -n scripts/ci/publish-npm-packages.sh; deno fmt --check --config=scripts/test.deno.json scripts/ci/publish-npm-packages.test.ts; deno lint --config=scripts/test.deno.json scripts/ci/publish-npm-packages.test.ts; deno check --config=scripts/test.deno.json --frozen scripts/ci/publish-npm-packages.test.ts; git diff --check.

Tested: deno task verify:quick.

Not-tested: ./scripts/hooks/pre-push is red before E2E execution because it references missing tests/e2e/playwright.config.ts; deno task test:e2e:playwright is red from mixed Playwright 1.60.0 and 1.59.0 loads; full deno test was interrupted after unrelated hosted/tool/cache network timeout failures.
Copilot AI review requested due to automatic review settings August 3, 2026 10:13
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Follow-up pushed in 993a3ca68249506c7fc390184c0467f3040dce06.

Addressed the remaining delimiter leak in scripts/ci/publish-npm-packages.sh: fallback Bearer, token=, _authToken=, POSIX, Windows, UNC, and file:// redaction now stops before closing quotes, ), ], and commas instead of consuming those delimiters.

Regression coverage in scripts/ci/publish-npm-packages.test.ts now covers quoted bearer/query/auth tokens plus parenthesized and comma-delimited POSIX, Windows, UNC, and file:// paths.

Verification:

  • RED confirmed first: focused test failed on the prior branch because the sanitizer consumed trailing quotes/commas/parentheses.
  • deno test --config=scripts/test.deno.json --frozen --allow-all scripts/ci/publish-npm-packages.test.ts -> passed, 1 test / 5 steps.
  • bash -n scripts/ci/publish-npm-packages.sh -> passed.
  • deno fmt --check --config=scripts/test.deno.json scripts/ci/publish-npm-packages.test.ts -> passed.
  • deno lint --config=scripts/test.deno.json scripts/ci/publish-npm-packages.test.ts -> passed.
  • deno check --config=scripts/test.deno.json --frozen scripts/ci/publish-npm-packages.test.ts -> passed.
  • git diff --check -> passed.
  • deno task verify:quick -> passed.

Broader gates not green for unrelated existing/tooling issues:

  • ./scripts/hooks/pre-push failed before E2E execution because it references missing tests/e2e/playwright.config.ts.
  • deno task test:e2e:playwright failed before running tests due mixed Playwright 1.60.0 and 1.59.0 loads.
  • Full deno test --no-check --allow-all --unstable-worker-options --unstable-net was interrupted after unrelated hosted/tool/cache network timeout failures had already made the run red.

No merge queued.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 3 changed files in this pull request and generated no new comments.

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Codex exact-head review and merge confidence

Reviewed SHA: 993a3ca68249506c7fc390184c0467f3040dce06

Findings: none.

Evidence:

  • Reviewed the exact origin/main...993a3ca68249506c7fc390184c0467f3040dce06 diff: scripts/ci/publish-npm-packages.sh, scripts/ci/publish-npm-packages.test.ts, and scripts/deno.lock.
  • The sanitizer now redacts Bearer, query-token, _authToken, POSIX, Windows, UNC, and file:// path forms without consuming closing quotes, parentheses, brackets, or comma delimiters.
  • The npm registry URL remains visible, while fixture credentials and local path prefixes are absent from sanitized stderr.
  • The existing E404 branch still preserves the trusted-publisher bootstrap guidance for genuinely missing package names, and non-E404 failures still fail closed with sanitized diagnostics only.
  • The lockfile addition is limited to the BDD test import graph needed by the updated script test under --frozen.
  • The only review thread is resolved and outdated.
  • Exact-head GitHub CI is green, including format, lint, typecheck, integration, all 8 coverage shards, unit, coverage gate, binary E2E, npm smoke, sentry packages, CodeQL, CLA, and CodeRabbit.

Local verification on the reviewed head:

  • npx --yes deno@2.7.7 test --config=scripts/test.deno.json --frozen --allow-all scripts/ci/publish-npm-packages.test.ts -> 1 passed / 5 steps, 0 failed.
  • bash -n scripts/ci/publish-npm-packages.sh -> passed.
  • npx --yes deno@2.7.7 check --config=scripts/test.deno.json --frozen scripts/ci/publish-npm-packages.test.ts -> passed.
  • npx --yes deno@2.7.7 fmt --check --config=scripts/test.deno.json scripts/ci/publish-npm-packages.test.ts -> passed.
  • npx --yes deno@2.7.7 lint --config=scripts/test.deno.json scripts/ci/publish-npm-packages.test.ts -> passed.
  • git diff --check origin/main...HEAD -> passed.

Merge confidence: 95%.

Reasoning: the change is narrow, release-script only, covered by delimiter-specific regressions and full exact-head CI, and directly addresses the previously confirmed diagnostic redaction gap. Residual risk is limited to unobserved npm diagnostic formatting variants outside the covered quoted, bracketed, parenthesized, comma-delimited, POSIX, Windows, UNC, file URI, Bearer, query-token, and _authToken forms.

Review-Gate:
Reviewer: Codex
Reviewed-SHA: 993a3ca
Score: 95/100
Actionable-Findings: 0
Verdict: APPROVE

@kojiwakayama
kojiwakayama added this pull request to the merge queue Aug 3, 2026
Merged via the queue into main with commit f92686a Aug 3, 2026
31 checks passed
@kojiwakayama
kojiwakayama deleted the fix/npm-release-diagnostic-redaction branch August 3, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants