Follow-up to #19. The current composite Action pins the top-level npm version but resolves transitive dependencies at runtime. A fixed JS bundle could remove install-time resolution, but the public package-spec input supports alternate/test tarballs and must retain deliberate semantics.
Compare an isolated lockfile/npm ci implementation with a bundled runtime: reproducibility, measured checkout/download size, cold execution time, maintenance/update cost, security surface and Marketplace compatibility.
Acceptance:
- Prototype bundling of ESM, dynamic imports and puppeteer-core paths; measure size rather than estimating.
- Build twice from locked npm ci and compare bytes; add stale-bundle detection.
- Preserve root and compatibility Action paths, package-spec, advisory/blocking modes, score/report outputs and failure behavior.
- Review dependencies/licenses and document rebuild/release ownership.
- Keep scoring/CLI/API contracts unchanged.
No runtime rewrite or production publication is authorized by this follow-up. Technical comparison is in docs/action-reproducibility.md in #19.
Follow-up to #19. The current composite Action pins the top-level npm version but resolves transitive dependencies at runtime. A fixed JS bundle could remove install-time resolution, but the public package-spec input supports alternate/test tarballs and must retain deliberate semantics.
Compare an isolated lockfile/npm ci implementation with a bundled runtime: reproducibility, measured checkout/download size, cold execution time, maintenance/update cost, security surface and Marketplace compatibility.
Acceptance:
No runtime rewrite or production publication is authorized by this follow-up. Technical comparison is in docs/action-reproducibility.md in #19.