fix(pi): isolate resolved package builds

This commit is contained in:
2026-08-16 00:20:30 +02:00
parent 5a657a67e8
commit 3e0c864c85
6 changed files with 96 additions and 5 deletions
+11 -2
View File
@@ -43,7 +43,13 @@ func newNPMRegistryClient(client *http.Client) *npmRegistryClient {
if client == nil {
client = &http.Client{Timeout: registryTimeout}
}
return &npmRegistryClient{client: client}
bounded := *client
bounded.CheckRedirect = rejectRegistryRedirect
return &npmRegistryClient{client: &bounded}
}
func rejectRegistryRedirect(request *http.Request, _ []*http.Request) error {
return fmt.Errorf("Pi registry redirect to %s is not allowed", request.URL.Redacted())
}
// LatestStable returns the greatest released semantic version. npm's dist-tag is not trusted as
@@ -99,7 +105,10 @@ func (c *npmRegistryClient) LatestStable(ctx context.Context, packageName string
return "", errors.New("Pi registry response is invalid")
}
version, err := parseSemanticVersion(rawVersion)
if err != nil || version.prerelease != "" {
if err != nil {
return "", errors.New("Pi registry response contains an invalid semantic version key")
}
if version.prerelease != "" {
continue
}
if !found || selected.less(version) {