Repository navigation
Bump lyhu/tunnel to 0.3.3 - #158
github-actions[bot] wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
Needs from you: nothing, changes requested
@lyhu, paseo-plugin-tunnel 0.3.3 can't merge yet. The code change is fine; the next release needs these four changes, and the bump workflow opens a fresh pull request when it is published:
- Add
OVERVIEW.mdnext topaseo-plugin.json. The registry requires one for every new version, and yours replaces the registry copyplugins/lyhu/tunnel.md. You can start from that copy without its last "imported from paseo.cafe" line, but change "Paseo 0.8.0 or newer" to 0.10.3, which is what 0.3.3 requires. The shape is inREVIEW.md: what it is and does, how it works if needed, setup, then what it reads or sends and where and known limits, with no installation steps. - Regenerate
npm-shrinkwrap.jsonso the manifest's build command works on npm 10 (the npm that ships with Node 22). On npm 10.9.3 it fails today:The 0.3.3 lockfile dropped thenpm ci --omit=dev --ignore-scripts --no-audit --no-fund npm error code EUSAGE npm error Missing: esbuild@0.28.2 from lock filevitest/node_modules/esbuildand@esbuild/*0.28.2 entries that npm 10 still expects. 0.3.2 installs on npm 10. - Point every lockfile entry's
resolvedathttps://registry.npmjs.org/. All 520 entries resolve onregistry.npmmirror.comtoday. Their integrity values match the public registry, but the registry requiresresolvedon it. - Add at least one screenshot as a
mediaarray inpaseo-plugin.json, for example"media": ["images/ingress-list.png", "images/egress-list.png"]from yourmainbranch, included in the packagefiles. The plugin adds a sidebar item and a page, andREVIEW.mdrequires an image for any plugin with UI.
Nothing else needs to change.
Review data
- Artifact: npm
paseo-plugin-tunnel0.3.3 (from 0.3.2),https://registry.npmjs.org/paseo-plugin-tunnel/-/paseo-plugin-tunnel-0.3.3.tgz. npmgitHeadisf557f7996f82d279bd5e2f3623540cece45befe1, tagv0.3.3. No npm provenance. - Integrity: SHA-512 of both tarballs matches the record (old and new pin) and npm's
dist.integrityfor 0.3.3. - Validation:
npm testpasses (140/140).node scripts/validate.ts --online --changedfails with one error:lyhu/tunnel/OVERVIEW.md is required. - Extracted and inspected: both tarballs, extracted and diffed locally. Five files change:
paseo-plugin.json:4raisesrequirements.paseofrom>=0.8.0to>=0.10.3;package.jsonmoves@getpaseo/relay,@getpaseo/client, and@getpaseo/pluginfrom 0.8.0 to 0.10.3;npm-shrinkwrap.jsonfollows and drops 27 nested esbuild 0.28.2 entries;README.mdupdates version text;shared/version.ts:4setsPLUGIN_VERSIONto 0.3.3. No other source changes. - Install-time commands:
paseo-plugin.jsonbuildisnpm ci --omit=dev --ignore-scripts --no-audit --no-fund, which installs the shrinkwrap's production entries and runs no scripts. No manifestinstall.package.jsonhas nopreinstall,install,postinstall, orprepare. The command fails on npm 10.9.3 (above) and succeeds on npm 11. - Dependencies: runtime
@getpaseo/relay0.10.3 (relay end-to-end encryption),ws8.21.3 (relay WebSocket),zod4.5.4 (config and RPC validation), plustweetnaclandbase64-jsthrough the relay. Only the relay version changes. Shrinkwrap: 520 entries, each withintegrity, allresolvedonregistry.npmmirror.com. Entries with install scripts (esbuild,fsevents,workerd) are dev only and skipped by--omit=dev --ignore-scripts. - Hosts:
relay.paseo.sh:443by default or the relay from the config file (server/handlers.ts:14), the relay endpoint from an imported route offer (server/offer.ts:7-10), the user's ingress origin (server/ingress-runtime.ts:6-7),127.0.0.1for the self-test (server/probe.ts:61-64), and the egress listener (server/egress-runtime.ts:119,134). All serve the tunnel's purpose; none change in this bump. - Credentials and environment:
PASEO_HOME, falling back to the Paseo home directory (server/storage.ts:28), and the machine hostname as the ingress label (server/subsystem.ts:263). Unchanged. - Filesystem: writes only
tunnel/config.jsonunder the Paseo home, directory mode 0700 and file 0600, written atomically (server/storage.ts:37-70). Unchanged. - Execution: no
child_process,eval,new Function, or dynamicimport(). - Runtime installs: none.
- Source match: all 49 tarball files are byte-identical to
lyhu/paseo-plugin-tunnelatf557f79. - Listing media: none in the record or manifest. The plugin adds the "HTTP Tunnel" sidebar item and page (
index.client.tsx:5-11). - Overview: missing in the 0.3.3 package and in the repository at
f557f79. The registry copy states Paseo 0.8.0 as the minimum. - Decision: changes requested.
- Reviewed commit:
f159169c5a43b66d7727790c7402f3eb2645beaa
There was a problem hiding this comment.
I added your existing ingress/egress screenshots and corrected the registry overview to require Paseo 0.10.3. Publication remains blocked only on the installation lockfile. The earlier requests for an artifact overview, new screenshots and npm-only dependency URLs no longer apply.
Please regenerate npm-shrinkwrap.json with npm 10, publish a new package version containing it, and update this PR’s artifact pin. Confirm that npm ci --omit=dev --ignore-scripts --no-audit --no-fund succeeds with Node 22/npm 10 before publishing. The unchanged 0.3.3 lockfile lacks the nested esbuild version expected by npm 10, so the declared preparation command stops before the plugin loads. See the publishing guide’s build guidance.
Optional next release: ship your own OVERVIEW.md for the listing page, where installation is already shown; the registry page remains usable meanwhile. Overview format.
Review data
- Reviewed PR head:
eb97f886a0e425425c3b5b591f83c64b74a24eef; original artifact-bearing head:f159169c5a43b66d7727790c7402f3eb2645beaa. REVIEW.md blob:7268134d240de9e474c52480f4937af4e369a6e2. - Downloaded npm
paseo-plugin-tunnel0.3.2 and 0.3.3 tarballs from their pinned registry.npmjs.org URLs. Both SHA-512 values match their records and npm version metadata. No provenance reported. Archive paths were checked before extraction; 49 regular files each. - Independently compared the artifacts: README, manifest version requirement, package version/SDK dependencies, shrinkwrap and shared version constant change. Runtime tunnel source is unchanged.
- Preparation: manifest invokes
npm ci --omit=dev --ignore-scripts --no-audit --no-fund; no package lifecycle scripts. Shrinkwrap has 520 locked registry.npmmirror.com entries with integrity. Five production packages: relay 0.10.3, ws 8.21.3, zod 4.5.4, tweetnacl 1.0.3, base64-js 1.5.1. Mirror origins alone are not a policy blocker. - Packaging evidence: the prior review recorded npm 10.9.3 failing with
Missing: esbuild@0.28.2 from lock file. Fresh integrity verification identifies the same artifact; static inspection confirms Vite’s nested esbuild peer range^0.27.0 || ^0.28.0, root esbuild 0.25.12 and no nested lock entry. Installation was not rerun because plugin/dependency execution is forbidden. - Access scope checked: configured relay and ingress origins, imported offer secrets, owner-only tunnel configuration selected through PASEO_HOME. Existing HTTP forwarding is purposeful and unchanged. Production dependency internals were not re-audited because installation remains blocked; this is not a completed security approval.
- Registry edits: added two pinned HTTPS PNG screenshots, visually inspected and checked as image/png; updated the existing overview’s version requirement. Trusted current-main online validation passes.
- No plugin, dependency, install or build code executed. Not approved or merged. No linked submission issue was found.
lyhu/tunnel: {"kind":"npm","package":"paseo-plugin-tunnel","version":"0.3.2","resolved":"https://registry.npmjs.org/paseo-plugin-tunnel/-/paseo-plugin-tunnel-0.3.2.tgz","integrity":"sha512-y+L4gbLnYE8qCA3BQEr2sPlVk3+zcAqSRPs6skY6lHzF5gLMaFINLJSod+4zzTTyHp0sNcJodk0G7QsHDb8+Qw=="} -> {"kind":"npm","package":"paseo-plugin-tunnel","version":"0.3.3","resolved":"https://registry.npmjs.org/paseo-plugin-tunnel/-/paseo-plugin-tunnel-0.3.3.tgz","integrity":"sha512-xoCAoTnhMn2B6GXnWFIz+iKlI+4h+XBFwWK7tFErpGUi5od7PgLNEupcFYL8SI3unpN3c91d537z+R88OWKBjA=="}No npm provenance for this version. Review the tarball diff below, not the repository.
Submitted by @lyhu.
Merging approves this version. The published index keeps pointing at the previous one until then.
Artifact diff
-Paseo 0.8 installs from GitHub:
+Paseo 0.10.3 installs from GitHub:
This version has no OVERVIEW.md. The registry requires one to update a listing; the bump cannot merge until the repository adds it.
Inline validation failed. See the Bump workflow log.