build(reproducibility): restack deterministic npm controls after nanoid - #89
build(reproducibility): restack deterministic npm controls after nanoid#89seonghobae wants to merge 34 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by clean protected-main successor #91 after #76 integrated. Fresh #91 exact-head evidence is now terminal-success for application |
Purpose
Controlled dependency-ordered replacement for closed superseded #78. This Draft starts from exact #76 so
nanoid@3.3.17is present before broader package-manager/install-script controls. No #78 check/review evidence transfers.Fresh identity
fix/nanoid-cve-2026-67213/ fix(security): update transitive nanoid for CVE-2026-67213 #76 at independently resolvede0106ce16b7b8b493f46bf075ec5baf58762bd95.adcc42d2b0fec3106faabb59bbf7e79124714f7aonbuild/deterministic-npm-toolchain-after-nanoid.Replayed unique controls
24.19.0/ npm11.17.0exact repository/CI identity;strict-allow-scripts=truewith reviewed lifecycle-script identities;postinstallcannot execute;npm ci --legacy-peer-deps=false --install-links=falsecontract;## Unreleasedchangelog evidence.Representative #78 artifacts were independently preserved before #78 closed; current replacement additionally proves predecessor integration and CHANGELOG contracts.
Test-first CHANGELOG completion
96cdc4d37d4e516143217cd4dcbe42210da00853: RED contract required Node/npm identity,strict-allow-scripts=true, and schema-v2 control under## Unreleased.31350000282: exact RED, 691/692 tests with only the missing changelog contract failing.adcc42d2b0fec3106faabb59bbf7e79124714f7a: GREEN bounded changelog addition.Newly proven sibling overlap with #80
Fresh compare proves #89 and #80 are diverged siblings with merge base exactly #76. They do not share production/package-manager files, and #89 does not modify
AGENTS.md, but both modifyCHANGELOG.mdunder## Unreleased:An unrefreshed sibling integrated after the other can conflict with or omit changelog evidence. This is a convergence/traceability hazard, not a reason to mix the implementations now.
After #76, #89 can stabilize independently from #87 because #87 changes only
AGENTS.md+ governance audit/test. The safest current order is to integrate/refetch #87 and #89 on the protected lineage first, then rebuild/refresh #80's unique work onto their combined protected state so #80 preserves bothAGENTS.mdandCHANGELOG.md. Old sibling evidence does not transfer and no artificial retarget may manufacture ancestry.Current exact-head proof
For
adcc42d2b0fec3106faabb59bbf7e79124714f7a:ci31350201695: terminal success; exact source/live predecessor binding, Node/npm identity, lockfile control, frozen install, 71/71 files and 692/692 tests, configured owned statements/branches/functions/lines 100%, real unreviewed-postinstall refusal, doctoring/CHANGELOG contracts, andnpm audit --audit-level=high0 vulnerabilities;reviewer-ci31350201710: terminal success;defer_until_trigger;Missing production KPI/provenance/security-validation/release/deployment/environment/revenue/transfer evidence remains intentionally non-passing and does not become acquisition evidence because this PR is green.
Acceptance boundary
CHANGELOG.mdentries.No force push, repair workflow, audit waiver, protection weakening, synthetic approval, release or deployment authority is introduced.
Related: #27, #29, #75, #76, #77, #79, #80, #87