Skip to content

Import aborakati/usage-monitor: suppress dependency lifecycle downloads #136

Description

@boudra

Keep aborakati/usage-monitor at Cafe commit 4b9758691237dda40665c6f107b569e7292dccbc out of the registry until its install path suppresses dependency lifecycle scripts.

paseo-plugin.json:6 runs npm ci --include=dev without --ignore-scripts. The exact lockfile includes esbuild 0.28.2 with postinstall: node install.js. Its registry tarball was downloaded and its SHA-512 verified for static inspection only.

In esbuild 0.28.2 install.js, when the platform optional package cannot resolve (lines 269–282), installUsingNPM invokes npm install in a fresh directory outside the plugin lockfile (lines 180–193). If that fails, lines 285–286 download the platform binary from registry.npmjs.org; lines 294–299 execute the selected binary to validate its version. This reachable fallback conflicts with the registry install-time pin policy, even though the normal path uses the locked optional package and the fallback checks a binary hash.

Use a manifest install/build path equivalent to npm ci --include=dev --ignore-scripts, then submit a new exact commit for review. The original Cafe pin is preserved and is not imported in this batch. No plugin or dependency code was executed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions