build(node): coordinate Node 22.22.2 floor with jsdom 30 - #896
build(node): coordinate Node 22.22.2 floor with jsdom 30#896seonghobae wants to merge 86 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent Please continue the existing canonical owner branch Validated RED: run 32021377546 job 95361595934 fails at A generator-produced repair already exists and is still downloadable: run 32018726491 / job 95353636943 generated Use that exact artifact as the provenance-preserving lock repair (do not hand-edit generated dependency graph), commit it to the existing branch, then verify current-head |
Canonical #779 Node/jsdom compatibility slice
This Draft advances issue #779 and remains deliberately downstream of canonical dependency-security owner #783. The PR targets protected
developso required protected-base workflows execute on its exact head; predecessor/base evidence never transfers.Exact current identity
c07e51639dbb7b44f57ff0aabc26ad793e691add.develop@acdbea6344fe1231c39535b575f4de35e4c607c9.dae5d3c8d055381d57c0971d8e40456711499476.99e6be9f0933df605c03c04e959b47c5c2405ca6; this Draft must be reconstructed/revalidated after fix(security): establish canonical npm, PDF.js, Nanoid, and Undici baseline #783 integrates rather than pretending that later root evidence is already ancestry.Compatibility contract
The branch requires:
>=22.22.2 <23with an explicit rejection regression for Node 22.22.1;10.9.8;^30.0.1;node-minimum-compatibilityexecution on exact Node 22.22.2 with npm 10.9.8 bootstrapped before dependency consumption;Dependency-root least-privilege carry-forward
Fresh exact logs showed this descendant still had the pre-repair
lock-validationcheckout credential behavior even after #783's owning lane identified and repaired it.The descendant was repaired without competing with #783:
ce45742e6c0c44e08a015d16ea012b4d6b2beac7adds the branch-specific regression requiringpersist-credentials: falseinside the frozen lock-validation job while retaining the Node 22.22.2-floor contract.c07e51639dbb7b44f57ff0aabc26ad793e691addadds the credential-free checkout option to this descendant's inheritedci.yml.Exact-head CI run
32097740686, job95592252535, proves the checkout now executes withpersist-credentials: falseand verifies npm10.9.8before reaching the already-known lock mismatch. The security repair therefore changed the intended authority boundary without masking the next RED condition.Current real RED boundary
The root
package-lock.jsonis still the pre-jsdom-30 graph. Exact-head frozennpm cifails because the manifest requires entries absent from the lock, including:jsdom@30.0.1;@asamuzakjp/css-color@6.0.7;@asamuzakjp/dom-selector@8.3.2;undici@8.10.0; andwhatwg-url@17.1.0.This is not bypassed or hand-edited. The lock must be regenerated on the correct post-#783 ancestry with the approved npm 10.9.8 generator and then revalidated through frozen consumption. The closed Dependabot #760 graph is reference evidence only; its checks/reviews/generator provenance do not transfer.
Accordingly, exact-head
ci,node-minimum-compatibility, andbuild-baselineare currently terminal-failure/non-passing at the stale-lock boundary. Other queued or incomplete workflows are also non-passing until terminal.Merge gate
Keep Draft and unmerged until #783 reaches protected
develop, this branch is deliberately reconstructed on the resulting live base, the lock is generated by the approved toolchain, and one unchanged exact head has every applicable repository/central CI, security, SAST, SBOM/supply-chain, coverage/docstring, build/package/release and review gate terminal-success; zero valid unresolved findings; a qualifying independent non-author last-push approval; and ordinary branch-protection acceptance.Never hand-edit generated dependency provenance, weaken a gate, reuse predecessor evidence, self-approve, or treat queued/pending/skipped/cancelled/failed/model-only evidence as success.