Skip to content

fix(release): execute root consumers against the packed tarball #291

Description

@seonghobae

Current authoritative state

The packed-root-consumer release-evidence defect is repaired on canonical single-writer Draft PR #292 / branch fix/packed-root-consumer-isolation-291. Protected shipped truth remains exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact #292 head is 147f317ca07d8fccf6b69ff220aba0bf971837ce. Any earlier issue/PR prose naming bfdd218caf41575cf750dcb03172a6896c4ee567 or its workflow generations as current is predecessor evidence.

Current verification creates one real npm pack --json --ignore-scripts --pack-destination tarball, validates inventory/export metadata from that exact archive, extracts those exact bytes beneath an isolated consumer node_modules/@contextualwisdomlab/cwl-editor, and executes ESM/CommonJS/subpath/strict-TypeScript consumers from that isolated tree. Resolution is canonicalized and proven inside the extracted package before execution. The current repair closes a validation-to-use gap by importing/requiring the exact canonical entrypoint that passed containment validation rather than resolving by package name again after the check.

This is Inkspan-owned release/package evidence only. It adds no registry installation, workspace link, lifecycle-script execution, network, credential, database, model/provider, transport, persistence, authorization, tenancy, deployment or durable-audit authority.

Test-first lineage

  • 1e6705ed39b18161cf874bffec5e0d3bd88710c9 failed in test setup and is not accepted as product RED.
  • Corrected RED 065346eb01a7ee4740ce4086c6cc15e8d91a7114, CI 31653280023, proved protected verification used npm pack --dry-run plus repository self-reference.
  • First implementation e9cf52a92ec14acd1f9330de04503fbd3d4f9dd3, CI 31654244618, exposed that a consumer nested under the repository package scope could still self-resolve to the checkout.
  • A later exact-current inspection found the verifier validated a resolved packed entry and then executed a fresh package-name resolution, leaving validation and use separable.
  • Test-first contract on the current lane requires ESM/CommonJS execution to use only the exact canonical module entries that passed containment validation; current GREEN head is 147f317ca07d8fccf6b69ff220aba0bf971837ce.

Exact-current-head evidence

For exact head 147f317ca07d8fccf6b69ff220aba0bf971837ce against protected main@3b38ead2d00f44eb578d0689087b9293b3dabe1e at the latest fresh refetch:

  • CI 32445567032: completed / success; build/test checked out exact head, the new packed-entry contract passed, 145 files / 834 tests passed at 100% aggregate statement/branch/function/line coverage, and verify:package executed the changed verifier successfully;
  • SAST Semgrep 32445566914: completed / success;
  • Security Scan 32445566963: completed / success;
  • qualifying independent approval remains absent;
  • unresolved inline review threads: 0;
  • PR fix(release): verify root consumers from packed tarball #292 remains Draft and mechanically mergeable.

All observed repository-owned exact-head workflows are terminal success. Repository exact-head technical success does not substitute for qualifying independent approval, separately applicable central workflows, or then-live governance. Absent review remains non-passing and predecessor evidence does not transfer.

Integration boundary

Keep #292 Draft/unmerged while #118 owns exact protected v0.6.0 publication/provenance acceptance. Before any lifecycle transition refetch exact head/live base, rules/permissions, formal reviews/threads and every applicable repository/central workflow. Do not create a competing package-verifier writer, transfer predecessor evidence, self-approve, weaken gates, move protected main or fabricate release identity. Close this issue only after #292 integrates under then-live governance and the resulting protected generation proves the same package-consumer contract.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions