Skip to content

ci: guard against patch drift on the vendored harness tarballs - #318

Open
HuangLeijiana wants to merge 1 commit into
dataelement:mainfrom
HuangLeijiana:pr/ci-patch-drift-check
Open

ci: guard against patch drift on the vendored harness tarballs#318
HuangLeijiana wants to merge 1 commit into
dataelement:mainfrom
HuangLeijiana:pr/ci-patch-drift-check

Conversation

@HuangLeijiana

Copy link
Copy Markdown
Contributor

patch-package only replays the tracked patches during npm ci's postinstall and only on machines that run a fresh install; on a TTY a failed hunk also exits 0 unless --error-on-fail is passed, and the repo tests assert marker strings inside the patch text rather than whether a hunk still fits its context. A harness bump that shifts patch context could therefore ship silently.

Add scripts/verify-patches.mjs, which unpacks each vendored tarball from packages/harness-0.1.2-rc.1 into an isolated node_modules and replays exactly that patch with --error-on-fail (verified: 20/20 apply today), and a GitHub Actions job that runs it on any PR touching patches/, the vendored tarballs, or the lockfile — without downloading Electron. Also expose it as npm run verify:patches.

patch-package only replays the tracked patches during npm ci's
postinstall and only on machines that run a fresh install; on a TTY a
failed hunk also exits 0 unless --error-on-fail is passed, and the repo
tests assert marker strings inside the patch text rather than whether a
hunk still fits its context. A harness bump that shifts patch context
could therefore ship silently.

Add scripts/verify-patches.mjs, which unpacks each vendored tarball
from packages/harness-0.1.2-rc.1 into an isolated node_modules and
replays exactly that patch with --error-on-fail (verified: 20/20 apply
today), and a GitHub Actions job that runs it on any PR touching
patches/, the vendored tarballs, or the lockfile — without downloading
Electron. Also expose it as npm run verify:patches.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant