Skip to content

Review migration hold: custyhs/advanced-markdown #33

Description

@boudra

custyhs/advanced-markdown remains held at paseo-advanced-markdown@0.2.6, source tag v0.2.6 at 4fd38dec1ecf8f147e506af6eea3d392026b5d46. The remaining finding is installation-time browser provisioning:

  • The published manifest builds with node scripts/prepare-browser.mjs. When the pinned Chrome headless shell is absent, scripts/prepare-browser.mjs:101 downloads it; line 119 runs the executable with --version. This supports Mermaid rendering, but install-time download and execution bypasses the reviewed artifact pin. The new confirmation exception applies to runtime installs.

The published shrinkwrap's 39 dependency entries and worker lockfile's 200 entries all have public npm registry resolutions and integrity. The worker's npm ci permits puppeteer@25.11.0's install.mjs postinstall; that script and its invoked installer/configuration were read, and the plugin sets PUPPETEER_SKIP_DOWNLOAD=1, so the hook returns without browser installation. That hook alone is no longer a blanket hold. The source Git manifest's npm ci also permits esbuild and node-pty lifecycle branches, including esbuild's fallback package install/download if its platform package is absent.

The package/manifest rewrites and generated renderer files are explained by the tagged source's build and pack scripts. No plugin code or dependency lifecycle was executed during review.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions