Skip to content

feat(install): require npm provenance for platform packages - #2440

Merged
fengmk2 merged 10 commits into
voidzero-dev:mainfrom
kazupon:issue-1826-platform-package-provenance
Sep 18, 2026
Merged

fengmk2 merged 10 commits into
voidzero-dev:mainfrom
kazupon:issue-1826-platform-package-provenance

Conversation

@kazupon

@kazupon kazupon commented Aug 13, 2026

Copy link
Copy Markdown
Collaborator

Summary

Closes #1826.

Vite+ previously accepted platform package metadata without requiring npm provenance, allowing an unverified release binary to reach the download path.

Require supported SLSA provenance before downloading standard release binaries through the standalone installers, vp upgrade, and vp-setup.exe.

Changes

  • Validate dist.attestations.provenance.predicateType against SLSA v1 and v0.2 in the shared Rust resolver.
  • Fetch and validate exact platform metadata in both standalone installers.
  • Fail closed before tarball download for missing, malformed, spoofed, or unsupported provenance.
  • Add one mock registry fixture and entrypoint coverage for all four install and upgrade paths.

Testing

  • cargo test -p vp_setup registry: provenance parsing, error classification, and download ordering.
  • just check, just test, just lint: workspace compilation, tests, and Clippy.
  • Mock-registry E2E: rejection before download and acceptance of SLSA v1/v0.2 across the installer and upgrade entrypoints.
  • Official npm release smoke test: an existing provenance-backed release still installs.

@netlify

netlify Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for viteplus-preview canceled.

Name Link
🔨 Latest commit e579506
🔍 Latest deploy log https://app.netlify.com/projects/viteplus-preview/deploys/6a990f854213470008f23d79

@kazupon
kazupon marked this pull request as ready for review August 13, 2026 06:03
@kazupon
kazupon requested a review from fengmk2 August 13, 2026 06:28
@kazupon

kazupon commented Aug 13, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3c8979569f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/cli/install.sh Outdated
@fengmk2

fengmk2 commented Aug 21, 2026

Copy link
Copy Markdown
Member

@kazupon can you update install.ps1 too?

@fengmk2 fengmk2 self-assigned this Aug 21, 2026
@kazupon

kazupon commented Aug 23, 2026

Copy link
Copy Markdown
Collaborator Author

@fengmk2
Thanks!

If you're referring to the Codex path-spoofing finding, it was specific to install.sh, whose AWK parser previously flattened JSON paths into dot-joined strings. install.ps1 uses nested property access ($Metadata.dist.attestations.provenance.predicateType), so a dotted top-level key cannot satisfy the check.

I also added the dotted-top-level-key regression case to both installer test suites, and the PowerShell case rejects it.

Please let me know if you had a different PowerShell concern in mind 🙏

@fengmk2

fengmk2 commented Sep 10, 2026

Copy link
Copy Markdown
Member

@kazupon Thanks, I will verify it once, and if there are no issues, I will merge it.

@fengmk2

fengmk2 commented Sep 10, 2026

Copy link
Copy Markdown
Member

@kazupon I think we should wait for #2611 finish, the install flow will have a big refactor after that.

cc @liangmiQwQ

@kazupon

kazupon commented Sep 12, 2026

Copy link
Copy Markdown
Collaborator Author

@fengmk2 no problem!
I can wait for it!

@fengmk2

fengmk2 commented Sep 12, 2026

Copy link
Copy Markdown
Member

@kazupon #2611 was merged, you can continue now!

@kazupon

kazupon commented Sep 13, 2026

Copy link
Copy Markdown
Collaborator Author

@fengmk2
I've just fixed conflict!
You can check and review again!

@fengmk2

fengmk2 commented Sep 14, 2026

Copy link
Copy Markdown
Member

@codex review

@fengmk2 fengmk2 added test: e2e Auto run e2e tests test: install-e2e run vite install e2e test test: create-e2e Run `vp create` e2e tests test: sfw labels Sep 14, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T08:46:28.760002Z 5556537 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

Reviewed commit: 5556537b1b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@fengmk2
fengmk2 requested a review from liangmiQwQ September 14, 2026 09:58

@liangmiQwQ liangmiQwQ left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Other LGTM :)

Comment thread packages/cli/install.sh
Comment thread packages/cli/install.ps1
@fengmk2 fengmk2 added the preview-build Publish this PR's commits to the registry bridge as preview builds label Sep 16, 2026
@fengmk2 fengmk2 changed the title fix(install): require npm provenance for platform packages feat(install): require npm provenance for platform packages Sep 16, 2026
@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Registry bridge build (72b4732)

Warning

This build is from the fork kazupon/vite-plus and has not been reviewed.
Installing it runs that code on your machine. Build log

This commit build is published to the registry bridge, which serves these as ordinary npm versions (every other package proxies to npmjs):

Package Version
vite-plus 0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1
@voidzero-dev/vite-plus-core 0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1

Install the Vite+ CLI built from this commit, then migrate a project:

# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install.sh | VP_PR_VERSION=2440 VP_LEGACY_INSTALLER_URL=https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install-legacy.sh bash
# Windows (PowerShell)
$env:VP_PR_VERSION="2440"; $env:VP_LEGACY_INSTALLER_URL="https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install-legacy.ps1"; irm https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install.ps1 | iex

Or download the standalone Windows installer built from this commit:

Architecture Installer
x64 vp-setup-x86_64-pc-windows-msvc.exe
Arm64 vp-setup-aarch64-pc-windows-msvc.exe

GitHub requires you to sign in and downloads each installer as a ZIP artifact. Extract vp-setup.exe, then run it against this preview build:

.\vp-setup.exe --version "0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1" --registry "https://registry-bridge.viteplus.dev/"

After installing, upgrade the current project's vite-plus to this test build with:

vp migrate

Or point your package manager at the bridge registry https://registry-bridge.viteplus.dev/:

Package manager Registry config
npm / pnpm / Bun .npmrc: registry=https://registry-bridge.viteplus.dev/
Yarn (v2+) .yarnrc.yml: npmRegistryServer: "https://registry-bridge.viteplus.dev/"

Then pin the build (vite aliases to vite-plus-core; pnpm can use a catalog, npm an overrides entry):

{
  "devDependencies": {
    "vite-plus": "0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1",
    "vite": "npm:@voidzero-dev/vite-plus-core@0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1"
  }
}

fengmk2 commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

The standalone Windows preview installation command fails, because our bridge registry don't includes provenance field. We need to adapt to this issue.

.\vp-setup.exe --version "0.0.0-commit.85644fb20281e9210840bf413e7dc377ad65fcd4" --registry "https://registry-bridge.viteplus.dev/"

@kazupon

kazupon commented Sep 18, 2026

Copy link
Copy Markdown
Collaborator Author

What we were worried about has happened, hasn't it. 😅

What should we do about this PR?
Should we close it so we can explore other solutions?

@fengmk2

fengmk2 commented Sep 18, 2026

Copy link
Copy Markdown
Member

@kazupon Let me quickly make a change to skip the provenance check for requests to registry-bridge.viteplus.dev.
Then I will merge it.

@fengmk2
fengmk2 force-pushed the issue-1826-platform-package-provenance branch from 85644fb to ba11d25 Compare September 18, 2026 14:14
@fengmk2 fengmk2 added preview-build Publish this PR's commits to the registry bridge as preview builds and removed preview-build Publish this PR's commits to the registry bridge as preview builds labels Sep 18, 2026
@fengmk2
fengmk2 merged commit 2a8aba3 into voidzero-dev:main Sep 18, 2026
255 checks passed
fengmk2 added a commit that referenced this pull request Sep 22, 2026
…2780)

Vite+ now uses Vitest 5, and `vp migrate` helps Vitest 4 projects adopt
the new APIs and defaults. Standalone installs and upgrades now require
verified npm provenance for release binaries.

### Breaking Changes

#### Vitest 5

`vp test` and the public `vite-plus/test*` exports now use
`vitest@5.0.1`
([#2551](#2551)), by
@fengmk2.

| Area | Old | New |
| --- | --- | --- |
| Test runner | `vitest@4.1.11` | `vitest@5.0.1` |
| CLI Node.js range | `^20.19.0 \|\| ^22.18.0 \|\| >=24.11.0` |
`^22.18.0 \|\| ^24.11.0 \|\| >=26.0.0` |
| `vite-plus/test/runners` and `vite-plus/test/suite` | Vite+
compatibility exports | Use supported APIs from `vite-plus/test`; review
unsupported runner and expect plugins |
| `vite-plus/test/browser-webdriverio` | Bundled export | Use the
community `@vitest/browser-webdriverio` package |

Run `vp migrate` from the workspace root before you install the new
dependencies. The migrator updates supported config, source, benchmark,
command, and import changes. It reports manual work as `BLOCK` or
`REVIEW` items. See the [Vitest 5 migration
guide](https://viteplus.dev/guide/vitest-v5) for the full process.
Projects can stay on the prior release until their runtimes and tests
are ready.

#### `vp staged` runtime requirements

`vp staged` now uses `lint-staged@17.5.1`
([#2754](#2754)), by
@fengmk2.

| Requirement | Old | New |
| --- | --- | --- |
| Node.js for `vp staged` | The Vite+ CLI runtime range | `^22.22.1 \|\|
^24.11.0 \|\| >=26.0.0` |
| Git | No separate documented minimum | `>=2.32.0` |

Update Node.js and Git on developer machines and CI runners that execute
`vp staged` or its pre-commit hook. Other workflows do not use these
extra requirements.

### Highlights

- Standalone installers, `vp upgrade`, and `vp-setup.exe` now reject
release binaries without supported SLSA provenance
([#2440](#2440)), by
@kazupon.
- Installers now show progress and the exact shell activation command.
Download progress preserves earlier terminal output
([#2744](#2744),
[#2741](#2741)), by
@fengmk2.
- System-first runtime and package-manager shims now use a fallback
directory at the end of `PATH`. Setup restores missing package-manager
preferences
([#2758](#2758),
[#2763](#2763)), by
@liangmiQwQ and @fengmk2.
- `vp run` now finishes when background processes remain. Large file
traces run without caching instead of killing the task
([#2767](#2767),
[vite-task#675](voidzero-dev/vite-task#675)), by
@wan9chi.

### Features

- `vp add` now supports shared install options such as `--offline`,
`--frozen-lockfile`, and `--lockfile-only`
([#2722](#2722)), by
@jong-kyung.
- `vp pm patch` and `vp pm patch-commit` now use the native commands in
npm 12 and later
([#2736](#2736)), by
@jong-kyung.
- `vp rebuild` now supports Yarn Berry and forwards package names and
extra arguments
([#2761](#2761)), by
@jong-kyung.
- The bundled tools update `oxlint` `1.83.0` -> `1.85.0`,
`oxlint-tsgolint` `7.0.2001` -> `7.0.2002`, and `oxfmt` `0.68.0` ->
`0.70.0` ([#2745](#2745),
[#2773](#2773),
[#2778](#2778)), by
@voidzero-guard[bot]. These versions can flag or format code that passed
before. Run `vp fmt` after upgrading if CI runs `vp check`.

### Fixes & Enhancements

- `oxlint` and `oxfmt` no longer expose bin wrappers that conflict with
upstream packages. Editors must use `vp lint --lsp`, `vp fmt --lsp`, or
`vp fmt --stdin-filepath`
([#2672](#2672)), by
@fengmk2.
- `vp create vite:generator` now replaces catalog references for package
managers that do not support catalogs
([#2720](#2720)), by
@SaKaNa-Y.
- Unpinned npm projects now use the npm version bundled with the
selected Node.js runtime. The same policy works during migration
([#2742](#2742),
[#2748](#2748)), by
@liangmiQwQ.
- The CLI now loads its local versions module through a file URL,
including on Windows paths
([#2749](#2749)), by
@YanChenBai.
- Package-manager commands now use pnpm when the project has no detected
package manager
([#2750](#2750)), by
@liangmiQwQ.
- `vp migrate` now removes unused `@oxlint/plugins` dependencies after
it rewrites plugin imports
([#2751](#2751)), by
@fengmk2.
- `vp update --no-save` now warns that Yarn Classic and Yarn Berry do
not support the option
([#2762](#2762)), by
@jong-kyung.
- `vp migrate` now explains its `tsdown@0.23` compatibility settings and
links to removal guidance
([#2769](#2769)), by
@fengmk2.
- Environment setup now installs and diagnoses the official `pn` and
`pnx` aliases for pnpm
([#2770](#2770)), by
@iruoy.
- Cached tasks now receive GitHub Actions OIDC variables, so npm Trusted
Publishing works through `vp run`
([vite-task#691](voidzero-dev/vite-task#691)),
by @naokihaba.
- Automatic task input tracking now records file access from signal
handlers
([vite-task#687](voidzero-dev/vite-task#687)),
by @wan9chi.

### Refactor

- `vp lint`, `vp fmt`, and `vp check` now use native config discovery.
Package commands keep matching workspace-root settings, while explicit
config flags take precedence
([#2731](#2731)), by
@fengmk2.

### Chore

- Generated workflows and `vp migrate` now use `setup-vp@v1.21.1`,
including its installation fixes
([#2760](#2760),
[#2772](#2772)), by
@renovate[bot] and @fengmk2.

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| vite | `8.3.0` |
[`434e8e9`](vitejs/vite@434e8e9)
|
| rolldown | `1.2.9` |
[`5b4746e`](rolldown/rolldown@5b4746e)
|
| tsdown | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) |
| vitest | `5.0.1` | [npm](https://npmx.dev/package/vitest/v/5.0.1) |
| oxlint | `1.85.0` | [npm](https://npmx.dev/package/oxlint/v/1.85.0) |
| oxlint-tsgolint | `7.0.2002` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2002) |
| oxfmt | `0.70.0` | [npm](https://npmx.dev/package/oxfmt/v/0.70.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@YanChenBai, @iruoy

**Full Changelog**:
v0.3.3...v1.0.0-rc.0

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview-build Publish this PR's commits to the registry bridge as preview builds test: create-e2e Run `vp create` e2e tests test: e2e Auto run e2e tests test: install-e2e run vite install e2e test test: sfw

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reject Vite+ install script if the @voidzero-dev/vite-plus-cli-* package does not have provenance

3 participants