Skip to content

[quality] dist/index.js self-containment is unguarded — a leaked external require() passes the bundle suite #265

Description

@hivecommons-hive

Finding

action.yml runs dist/index.js directly (runs.main), on a runner that never installs node_modules. Every package the action imports therefore has to be inlined by ncc build. Nothing in the test suite guards that invariant:

  • __tests__/bundle/bundle.test.ts → is a syntactically valid bundle with no unresolved modules asserts only that node --check passes and that the bundle has no webpackMissingModule marker. That marker is emitted when ncc cannot resolve a module at build time. A module that is resolved but left external (ncc build -e <pkg>, a future webpack externals entry, or a dependency ncc decides not to inline) is emitted as a literal require("<pkg>") and trips neither check.
  • __tests__/bundle/runBundle.ts spawns the bundle with no cwd, i.e. from the repository root, where node_modules/ exists. A leaked require("js-yaml") resolves fine there, so every end-to-end case in the bundle suite stays green — and the action breaks only on a real runner with Cannot find module 'js-yaml'.

Verified on main @ c48bd6d: appending require("js-yaml") to dist/index.js leaves npx vitest run __tests__/bundle fully green. Today the bundle is clean — all 35 require() specifiers in dist/index.js are Node built-ins (fs, node:http, …) and @actions/core, @actions/github, @octokit/rest, js-yaml all appear as inlined node_modules/<pkg>/ modules — so this is a regression-risk finding, not a coverage gap.

Unit evidence (provenance): npm ci && npx vitest run --coverage on main @ c48bd6d, Node v26.10.0 → 69 files / 1447 tests, All files | 99.83 | 98.35 | 100 | 99.82. End-to-end evidence: the bundle suite is the e2e source and, per #235, emits no coverage data; this finding does not depend on it.

Recommendation

Add __tests__/bundle/selfContained.test.ts (new file, so it stays clear of the held PRs that edit bundle.test.ts) asserting:

Mutation check: with require("js-yaml") appended to the bundle the first assertion fails with expected [ 'js-yaml' ] to deeply equal [].

Priority

  • Impact: medium — a leaked external ships a bundle that is green in CI and fails on every consumer's first run
  • Effort: low

Filed by quality agent (hold-gated mode)


🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: c48bd6d

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Activity

  1. added
    qualityCreated by Hive for agent-filed issue provenance
    testingCreated by Hive for agent-filed issue provenance
    agent/qualityCreated by Hive for agent-filed issue provenance
    on Oct 2, 2026
  2. github-actions commented on Oct 2, 2026

    @github-actions
    Contributor

    Please add a kind label with /kind failing-test or /kind cleanup.

  3. added
    hive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmed
    hive/likely-doneHive verified that a merged PR references or claims this issue; pending confirmation
    and removed
    hive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmed
    on Oct 2, 2026
  4. hivecommons-hive commented on Oct 2, 2026

    @hivecommons-hive
    ContributorAuthor

    task-list sweep: 0 of 2 items ticked. Not closing yet — outstanding boxes remain.

    Outstanding items:

    Merged PRs referencing this issue so far:

    This comment is edited in place by the task-list sweep on every cycle; it is not duplicated.

  5. hivecommons-hive commented on Oct 3, 2026

    @hivecommons-hive
    ContributorAuthor

    Verified resolved on main @ 61577d5: #266 merged __tests__/bundle/selfContained.test.ts; suite green.


    🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 61577d5

    — hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenancehive/likely-doneHive verified that a merged PR references or claims this issue; pending confirmationneeds-kindqualityCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions