From 922a84b7137c27257fce90f89d8d479ac06cc0d6 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Tue, 28 Jul 2026 06:55:50 +0200 Subject: [PATCH 1/3] fix(release): make audit:prod cross-platform audit:prod used the POSIX-only "env -u npm_config_allow_scripts" prefix, which is not a command under Windows cmd.exe, so release:check and prepublishOnly fail there. CI is ubuntu-only so it never surfaced in the pipeline; it breaks a Windows contributor running the gate locally, and npm publish via prepublishOnly. Adopt the same Node helper the rest of the fleet now uses: it strips npm_config_allow_scripts from the environment, pins npm_config_userconfig to the platform null device, and spawns npm through a shell on win32 only. The shell flag is required rather than cosmetic: Node CVE-2024-27980 hardening refuses to execute .cmd files through spawn unless the shell option is set, so a helper spawning npm.cmd without it fails on Windows for a second, subtler reason. The argument vector is two constants with nothing interpolated, so enabling the shell introduces no injection surface. Not empirically verified on Windows - there is no Windows host here. POSIX behaviour is unchanged and verified: release:check passes end to end. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 378e850..b24b2de 100644 --- a/package.json +++ b/package.json @@ -26,7 +26,7 @@ "prepack": "npm run build", "typecheck": "tsc --noEmit", "check": "npm run typecheck", - "audit:prod": "env -u npm_config_allow_scripts npm audit --omit=dev --ignore-scripts", + "audit:prod": "node --input-type=module -e \"import { spawnSync } from 'node:child_process'; import { devNull } from 'node:os'; const env = { ...process.env, npm_config_userconfig: devNull, NPM_CONFIG_USERCONFIG: devNull }; for (const key of Object.keys(env)) if (key.toLowerCase() === 'npm_config_allow_scripts') delete env[key]; const win = process.platform === 'win32'; const r = spawnSync(win ? 'npm.cmd' : 'npm', ['audit', '--omit=dev'], { stdio: 'inherit', env, shell: win }); process.exit(r.status ?? 1);\"", "pack:dry-run": "npm pack --dry-run", "changelog": "pm-changelog --pm-root .agents/pm --mode prepend --output CHANGELOG.md --release-version-from-package --since-previous-tag --until-release-tag --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release", "changelog:full": "pm-changelog --pm-root .agents/pm --mode replace --output CHANGELOG.md --all-release-tags --release-version-from-package --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release", From b85e2213fd0205a825afc4e00df6d0d1f96855f1 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Tue, 28 Jul 2026 07:10:36 +0200 Subject: [PATCH 2/3] fix(manifest): align pm_min_version with the declared peer requirement manifest.json declared a pm_min_version older than the >=2026.7.28 peer requirement in package.json. The two disagreed about the floor, and the manifest promised support for a pm version this extension is neither built nor tested against - the activation tests run through the 2026.7.28 SDK harness. Set the manifest floor to 2026.7.28 so both declarations agree. Found by CodeRabbit on pm-presets; the same mismatch was present here. --- manifest.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifest.json b/manifest.json index 2751596..1c5ee96 100644 --- a/manifest.json +++ b/manifest.json @@ -5,7 +5,7 @@ "author": "@unbraind", "entry": "./dist/index.js", "priority": 50, - "pm_min_version": "2026.7.20", + "pm_min_version": "2026.7.28", "capabilities": [ "commands", "importers", From 004e8761285f14383a1ae173a037359103b03976 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Tue, 28 Jul 2026 07:13:25 +0200 Subject: [PATCH 3/3] fix(release): restore --ignore-scripts on the audit argv The cross-platform helper was adopted from pm-ops, whose argv was ["audit", "--omit=dev"] -- so switching to it silently dropped the --ignore-scripts flag the previous env -u form passed. That is a reduction in the gate relative to what it replaced, not an intended change. Restore it, so the only difference from the previous form is the platform handling. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index b24b2de..afb9af2 100644 --- a/package.json +++ b/package.json @@ -26,7 +26,7 @@ "prepack": "npm run build", "typecheck": "tsc --noEmit", "check": "npm run typecheck", - "audit:prod": "node --input-type=module -e \"import { spawnSync } from 'node:child_process'; import { devNull } from 'node:os'; const env = { ...process.env, npm_config_userconfig: devNull, NPM_CONFIG_USERCONFIG: devNull }; for (const key of Object.keys(env)) if (key.toLowerCase() === 'npm_config_allow_scripts') delete env[key]; const win = process.platform === 'win32'; const r = spawnSync(win ? 'npm.cmd' : 'npm', ['audit', '--omit=dev'], { stdio: 'inherit', env, shell: win }); process.exit(r.status ?? 1);\"", + "audit:prod": "node --input-type=module -e \"import { spawnSync } from 'node:child_process'; import { devNull } from 'node:os'; const env = { ...process.env, npm_config_userconfig: devNull, NPM_CONFIG_USERCONFIG: devNull }; for (const key of Object.keys(env)) if (key.toLowerCase() === 'npm_config_allow_scripts') delete env[key]; const win = process.platform === 'win32'; const r = spawnSync(win ? 'npm.cmd' : 'npm', ['audit', '--omit=dev', '--ignore-scripts'], { stdio: 'inherit', env, shell: win }); process.exit(r.status ?? 1);\"", "pack:dry-run": "npm pack --dry-run", "changelog": "pm-changelog --pm-root .agents/pm --mode prepend --output CHANGELOG.md --release-version-from-package --since-previous-tag --until-release-tag --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release", "changelog:full": "pm-changelog --pm-root .agents/pm --mode replace --output CHANGELOG.md --all-release-tags --release-version-from-package --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release",