fix(pi): isolate resolved package builds
This commit is contained in:
@@ -43,7 +43,13 @@ func newNPMRegistryClient(client *http.Client) *npmRegistryClient {
|
||||
if client == nil {
|
||||
client = &http.Client{Timeout: registryTimeout}
|
||||
}
|
||||
return &npmRegistryClient{client: client}
|
||||
bounded := *client
|
||||
bounded.CheckRedirect = rejectRegistryRedirect
|
||||
return &npmRegistryClient{client: &bounded}
|
||||
}
|
||||
|
||||
func rejectRegistryRedirect(request *http.Request, _ []*http.Request) error {
|
||||
return fmt.Errorf("Pi registry redirect to %s is not allowed", request.URL.Redacted())
|
||||
}
|
||||
|
||||
// LatestStable returns the greatest released semantic version. npm's dist-tag is not trusted as
|
||||
@@ -99,7 +105,10 @@ func (c *npmRegistryClient) LatestStable(ctx context.Context, packageName string
|
||||
return "", errors.New("Pi registry response is invalid")
|
||||
}
|
||||
version, err := parseSemanticVersion(rawVersion)
|
||||
if err != nil || version.prerelease != "" {
|
||||
if err != nil {
|
||||
return "", errors.New("Pi registry response contains an invalid semantic version key")
|
||||
}
|
||||
if version.prerelease != "" {
|
||||
continue
|
||||
}
|
||||
if !found || selected.less(version) {
|
||||
|
||||
Reference in New Issue
Block a user