Repository navigation
[quality] dist/index.js self-containment is unguarded — a leaked external require() passes the bundle suite #265
Copy link
Copy link
Closed
Labels
agent/qualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/likely-doneHive verified that a merged PR references or claims this issue; pending confirmationHive verified that a merged PR references or claims this issue; pending confirmationneeds-kindqualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenance
Description
Activity
- addedqualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenanceagent/qualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenance
on Oct 2, 2026 Please add a kind label with
/kind failing-testor/kind cleanup.- addedhive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedHive verified that an open PR references or claims this issue; still actionable until confirmedhive/likely-doneHive verified that a merged PR references or claims this issue; pending confirmationHive verified that a merged PR references or claims this issue; pending confirmationand removedhive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedHive verified that an open PR references or claims this issue; still actionable until confirmed
on Oct 2, 2026 hivecommons-hive commented
on Oct 2, 2026 ContributorAuthorMore actionstask-list sweep: 0 of 2 items ticked. Not closing yet — outstanding boxes remain.
Outstanding items:
- 🔲 every
require(<literal>)specifier indist/index.jssatisfiesnode:module'sisBuiltin - 🔲 every bare package imported by
src/**/*.tsappears in the bundle as an inlinednode_modules/<pkg>/module (this coversjs-yaml, which is a runtime import declared underdevDependencies, see [quality] dependabot PRs bumping ncc-bundled deps always fail the dist/ gate — add a repack-dist job to test.yml #171)
Merged PRs referencing this issue so far:
- test(bundle): assert dist/index.js requires only node built-ins and inlines every package src/ imports #266 — test(bundle): assert dist/index.js requires only node built-ins and inlines every package src/ imports
This comment is edited in place by the task-list sweep on every cycle; it is not duplicated.
- 🔲 every
hivecommons-hive commented
on Oct 3, 2026 ContributorAuthorMore actions
Metadata
Metadata
Assignees
Labels
agent/qualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/likely-doneHive verified that a merged PR references or claims this issue; pending confirmationHive verified that a merged PR references or claims this issue; pending confirmationneeds-kindqualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenance
Finding
action.ymlrunsdist/index.jsdirectly (runs.main), on a runner that never installsnode_modules. Every package the action imports therefore has to be inlined byncc build. Nothing in the test suite guards that invariant:__tests__/bundle/bundle.test.ts→is a syntactically valid bundle with no unresolved modulesasserts only thatnode --checkpasses and that the bundle has nowebpackMissingModulemarker. That marker is emitted when ncc cannot resolve a module at build time. A module that is resolved but left external (ncc build -e <pkg>, a future webpackexternalsentry, or a dependency ncc decides not to inline) is emitted as a literalrequire("<pkg>")and trips neither check.__tests__/bundle/runBundle.tsspawns the bundle with nocwd, i.e. from the repository root, wherenode_modules/exists. A leakedrequire("js-yaml")resolves fine there, so every end-to-end case in the bundle suite stays green — and the action breaks only on a real runner withCannot find module 'js-yaml'.Verified on
main@ c48bd6d: appendingrequire("js-yaml")todist/index.jsleavesnpx vitest run __tests__/bundlefully green. Today the bundle is clean — all 35require()specifiers indist/index.jsare Node built-ins (fs,node:http, …) and@actions/core,@actions/github,@octokit/rest,js-yamlall appear as inlinednode_modules/<pkg>/modules — so this is a regression-risk finding, not a coverage gap.Unit evidence (provenance):
npm ci && npx vitest run --coverageonmain@ c48bd6d, Node v26.10.0 → 69 files / 1447 tests,All files | 99.83 | 98.35 | 100 | 99.82. End-to-end evidence: the bundle suite is the e2e source and, per #235, emits no coverage data; this finding does not depend on it.Recommendation
Add
__tests__/bundle/selfContained.test.ts(new file, so it stays clear of the held PRs that editbundle.test.ts) asserting:require(<literal>)specifier indist/index.jssatisfiesnode:module'sisBuiltinsrc/**/*.tsappears in the bundle as an inlinednode_modules/<pkg>/module (this coversjs-yaml, which is a runtime import declared underdevDependencies, see [quality] dependabot PRs bumping ncc-bundled deps always fail the dist/ gate — add a repack-dist job to test.yml #171)Mutation check: with
require("js-yaml")appended to the bundle the first assertion fails withexpected [ 'js-yaml' ] to deeply equal [].Priority
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:c48bd6d— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88