Skip to content

test(attestations): keep require in call position for evidence gate - #234

Merged
John-David Dalton (jdalton) merged 1 commit into
mainfrom
test/fixture-module-cache
Sep 28, 2026
Merged

John-David Dalton (jdalton) merged 1 commit into
mainfrom
test/fixture-module-cache

Conversation

@jdalton

@jdalton John-David Dalton (jdalton) commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

The packed-attestations fixture read require.cache inside the isLoaded closure. The consumer-evidence collector invalidates a file's require-derived bindings when require is used as a value, so the fixture's dynamic pathToFileURL(load.resolve(...)) import — otherwise a supported statically resolvable pattern — stopped resolving. That has kept the fleet lib-usage aggregate producer red since the fixture landed, so the published aggregate is stale and the Verify public consumer usage evidence CI gate fails on every pull request.

Reads the shared module cache through an untracked require('node:module')._cache binding instead. Module._cache === require.cache === createRequire(...).cache on Node 26 (verified), so isLoaded observes the same cache the packed package loads into. require and load now appear only in call position.

Verified the collector resolves both @socketsecurity/lib leaves from the edited fixture.


Note

Low Risk
Test-only fixture change with no production or security impact; restores CI evidence aggregation behavior.

Overview
Fixes the packed attestations integration fixture so the consumer usage evidence collector can still statically resolve @socketsecurity/lib imports.

isLoaded() previously read require.cache, which counts as using require as a value and breaks resolution of the fixture’s pathToFileURL(load.resolve(...)) dynamic import pattern. The fixture now reads the same shared cache via require('node:module')._cache, leaving require and createRequire only in call position while preserving lazy-load assertions for sigstore-verify.js.

Reviewed by Cursor Bugbot for commit 708c25c. Configure here.

@jdalton
John-David Dalton (jdalton) merged commit f423e31 into main Sep 28, 2026
11 of 12 checks passed
@jdalton
John-David Dalton (jdalton) deleted the test/fixture-module-cache branch September 28, 2026 20:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant