feat(install): require npm provenance for platform packages - #2440
Conversation
✅ Deploy Preview for viteplus-preview canceled.
|
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3c8979569f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@kazupon can you update install.ps1 too? |
|
@fengmk2 If you're referring to the Codex path-spoofing finding, it was specific to install.sh, whose AWK parser previously flattened JSON paths into dot-joined strings. install.ps1 uses nested property access ($Metadata.dist.attestations.provenance.predicateType), so a dotted top-level key cannot satisfy the check. I also added the dotted-top-level-key regression case to both installer test suites, and the PowerShell case rejects it. Please let me know if you had a different PowerShell concern in mind 🙏 |
|
@kazupon Thanks, I will verify it once, and if there are no issues, I will merge it. |
|
@kazupon I think we should wait for #2611 finish, the install flow will have a big refactor after that. cc @liangmiQwQ |
|
@fengmk2 no problem! |
|
@fengmk2 |
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Registry bridge build (
|
| Package | Version |
|---|---|
vite-plus |
0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1 |
@voidzero-dev/vite-plus-core |
0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1 |
Install the Vite+ CLI built from this commit, then migrate a project:
# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install.sh | VP_PR_VERSION=2440 VP_LEGACY_INSTALLER_URL=https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install-legacy.sh bash# Windows (PowerShell)
$env:VP_PR_VERSION="2440"; $env:VP_LEGACY_INSTALLER_URL="https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install-legacy.ps1"; irm https://raw.githubusercontent.com/kazupon/vite-plus/72b4732adadea4f68ae4d26b32c644cf772c59d1/packages/cli/install.ps1 | iexOr download the standalone Windows installer built from this commit:
| Architecture | Installer |
|---|---|
| x64 | vp-setup-x86_64-pc-windows-msvc.exe |
| Arm64 | vp-setup-aarch64-pc-windows-msvc.exe |
GitHub requires you to sign in and downloads each installer as a ZIP artifact. Extract vp-setup.exe, then run it against this preview build:
.\vp-setup.exe --version "0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1" --registry "https://registry-bridge.viteplus.dev/"After installing, upgrade the current project's vite-plus to this test build with:
vp migrateOr point your package manager at the bridge registry https://registry-bridge.viteplus.dev/:
| Package manager | Registry config |
|---|---|
| npm / pnpm / Bun | .npmrc: registry=https://registry-bridge.viteplus.dev/ |
| Yarn (v2+) | .yarnrc.yml: npmRegistryServer: "https://registry-bridge.viteplus.dev/" |
Then pin the build (vite aliases to vite-plus-core; pnpm can use a catalog, npm an overrides entry):
{
"devDependencies": {
"vite-plus": "0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1",
"vite": "npm:@voidzero-dev/vite-plus-core@0.0.0-commit.72b4732adadea4f68ae4d26b32c644cf772c59d1"
}
}|
The standalone Windows preview installation command fails, because our bridge registry don't includes provenance field. We need to adapt to this issue. .\vp-setup.exe --version "0.0.0-commit.85644fb20281e9210840bf413e7dc377ad65fcd4" --registry "https://registry-bridge.viteplus.dev/" |
|
What we were worried about has happened, hasn't it. 😅 What should we do about this PR? |
|
@kazupon Let me quickly make a change to skip the provenance check for requests to registry-bridge.viteplus.dev. |
85644fb to
ba11d25
Compare
…2780) Vite+ now uses Vitest 5, and `vp migrate` helps Vitest 4 projects adopt the new APIs and defaults. Standalone installs and upgrades now require verified npm provenance for release binaries. ### Breaking Changes #### Vitest 5 `vp test` and the public `vite-plus/test*` exports now use `vitest@5.0.1` ([#2551](#2551)), by @fengmk2. | Area | Old | New | | --- | --- | --- | | Test runner | `vitest@4.1.11` | `vitest@5.0.1` | | CLI Node.js range | `^20.19.0 \|\| ^22.18.0 \|\| >=24.11.0` | `^22.18.0 \|\| ^24.11.0 \|\| >=26.0.0` | | `vite-plus/test/runners` and `vite-plus/test/suite` | Vite+ compatibility exports | Use supported APIs from `vite-plus/test`; review unsupported runner and expect plugins | | `vite-plus/test/browser-webdriverio` | Bundled export | Use the community `@vitest/browser-webdriverio` package | Run `vp migrate` from the workspace root before you install the new dependencies. The migrator updates supported config, source, benchmark, command, and import changes. It reports manual work as `BLOCK` or `REVIEW` items. See the [Vitest 5 migration guide](https://viteplus.dev/guide/vitest-v5) for the full process. Projects can stay on the prior release until their runtimes and tests are ready. #### `vp staged` runtime requirements `vp staged` now uses `lint-staged@17.5.1` ([#2754](#2754)), by @fengmk2. | Requirement | Old | New | | --- | --- | --- | | Node.js for `vp staged` | The Vite+ CLI runtime range | `^22.22.1 \|\| ^24.11.0 \|\| >=26.0.0` | | Git | No separate documented minimum | `>=2.32.0` | Update Node.js and Git on developer machines and CI runners that execute `vp staged` or its pre-commit hook. Other workflows do not use these extra requirements. ### Highlights - Standalone installers, `vp upgrade`, and `vp-setup.exe` now reject release binaries without supported SLSA provenance ([#2440](#2440)), by @kazupon. - Installers now show progress and the exact shell activation command. Download progress preserves earlier terminal output ([#2744](#2744), [#2741](#2741)), by @fengmk2. - System-first runtime and package-manager shims now use a fallback directory at the end of `PATH`. Setup restores missing package-manager preferences ([#2758](#2758), [#2763](#2763)), by @liangmiQwQ and @fengmk2. - `vp run` now finishes when background processes remain. Large file traces run without caching instead of killing the task ([#2767](#2767), [vite-task#675](voidzero-dev/vite-task#675)), by @wan9chi. ### Features - `vp add` now supports shared install options such as `--offline`, `--frozen-lockfile`, and `--lockfile-only` ([#2722](#2722)), by @jong-kyung. - `vp pm patch` and `vp pm patch-commit` now use the native commands in npm 12 and later ([#2736](#2736)), by @jong-kyung. - `vp rebuild` now supports Yarn Berry and forwards package names and extra arguments ([#2761](#2761)), by @jong-kyung. - The bundled tools update `oxlint` `1.83.0` -> `1.85.0`, `oxlint-tsgolint` `7.0.2001` -> `7.0.2002`, and `oxfmt` `0.68.0` -> `0.70.0` ([#2745](#2745), [#2773](#2773), [#2778](#2778)), by @voidzero-guard[bot]. These versions can flag or format code that passed before. Run `vp fmt` after upgrading if CI runs `vp check`. ### Fixes & Enhancements - `oxlint` and `oxfmt` no longer expose bin wrappers that conflict with upstream packages. Editors must use `vp lint --lsp`, `vp fmt --lsp`, or `vp fmt --stdin-filepath` ([#2672](#2672)), by @fengmk2. - `vp create vite:generator` now replaces catalog references for package managers that do not support catalogs ([#2720](#2720)), by @SaKaNa-Y. - Unpinned npm projects now use the npm version bundled with the selected Node.js runtime. The same policy works during migration ([#2742](#2742), [#2748](#2748)), by @liangmiQwQ. - The CLI now loads its local versions module through a file URL, including on Windows paths ([#2749](#2749)), by @YanChenBai. - Package-manager commands now use pnpm when the project has no detected package manager ([#2750](#2750)), by @liangmiQwQ. - `vp migrate` now removes unused `@oxlint/plugins` dependencies after it rewrites plugin imports ([#2751](#2751)), by @fengmk2. - `vp update --no-save` now warns that Yarn Classic and Yarn Berry do not support the option ([#2762](#2762)), by @jong-kyung. - `vp migrate` now explains its `tsdown@0.23` compatibility settings and links to removal guidance ([#2769](#2769)), by @fengmk2. - Environment setup now installs and diagnoses the official `pn` and `pnx` aliases for pnpm ([#2770](#2770)), by @iruoy. - Cached tasks now receive GitHub Actions OIDC variables, so npm Trusted Publishing works through `vp run` ([vite-task#691](voidzero-dev/vite-task#691)), by @naokihaba. - Automatic task input tracking now records file access from signal handlers ([vite-task#687](voidzero-dev/vite-task#687)), by @wan9chi. ### Refactor - `vp lint`, `vp fmt`, and `vp check` now use native config discovery. Package commands keep matching workspace-root settings, while explicit config flags take precedence ([#2731](#2731)), by @fengmk2. ### Chore - Generated workflows and `vp migrate` now use `setup-vp@v1.21.1`, including its installation fixes ([#2760](#2760), [#2772](#2772)), by @renovate[bot] and @fengmk2. ### Bundled Versions | Tool | Version | Source | | --- | --- | --- | | vite | `8.3.0` | [`434e8e9`](vitejs/vite@434e8e9) | | rolldown | `1.2.9` | [`5b4746e`](rolldown/rolldown@5b4746e) | | tsdown | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) | | vitest | `5.0.1` | [npm](https://npmx.dev/package/vitest/v/5.0.1) | | oxlint | `1.85.0` | [npm](https://npmx.dev/package/oxlint/v/1.85.0) | | oxlint-tsgolint | `7.0.2002` | [npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2002) | | oxfmt | `0.70.0` | [npm](https://npmx.dev/package/oxfmt/v/0.70.0) | ### Upgrade ```bash vp upgrade ``` ### New Contributors @YanChenBai, @iruoy **Full Changelog**: v0.3.3...v1.0.0-rc.0 --- Merging this PR will trigger the release workflow. --------- Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com> Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Summary
Closes #1826.
Vite+ previously accepted platform package metadata without requiring npm provenance, allowing an unverified release binary to reach the download path.
Require supported SLSA provenance before downloading standard release binaries through the standalone installers,
vp upgrade, andvp-setup.exe.Changes
dist.attestations.provenance.predicateTypeagainst SLSA v1 and v0.2 in the shared Rust resolver.Testing
cargo test -p vp_setup registry: provenance parsing, error classification, and download ordering.just check,just test,just lint: workspace compilation, tests, and Clippy.