Repository navigation
fix: restore homepage CSP and patch CI security advisories - #8
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Astro homepage bypasses Next.js response headers and currently serves without the CSP already configured for
/. Restore that exact policy on the static homepage and Worker-wrapped asset responses, preserving directives, cache headers and compression behavior. Production smoke now rejects missing, empty or different policies.Regression tests exercise identity/gzip/304 responses, unaffected routing and the existing CLI path-with-spaces check. The first full CI attempt exposed a JSDOM Blob fixture problem; importing Node Blob corrected it without weakening the assertions. The second attempt passed all 524 tests in 89 files, then failed on two newly reported dependency advisories.
Address those advisories with same-line patch floors: source-map-js 1.2.2 and proxy-addr 2.0.8. No direct dependencies, scripts or audit exceptions change. pnpm 10.33.2 generated the lockfile on an existing GitHub runner with lifecycle scripts disabled; independent review verified the artifact digest, registry integrity values and scoped dependency graph diff. The temporary helper workflow and manifest were restored exactly; this PR keeps the normal CI workflow unchanged.
Validation: focused Node checks pass; Biome passes. Exact-head normal full quality and production-build CI are required before merge. Mocked bindings are not deployed Cloudflare or browser proof.
Refs #3. The issue remains open for deployed policy acceptance, the mobile Close-control verification owned by the footer work, and remaining capture/privacy requirements.