From 5b6fec939ab5fd1c4d43bda8c45246a361b90e80 Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 25 Aug 2026 16:47:56 +0200 Subject: [PATCH] fix(ci): isolate npm release configuration --- scripts/test-verify-schema-v3-only.sh | 6 ++++++ scripts/verify-schema-v3-only-release.sh | 13 +++++++++---- 2 files changed, 15 insertions(+), 4 deletions(-) diff --git a/scripts/test-verify-schema-v3-only.sh b/scripts/test-verify-schema-v3-only.sh index c0e1a340..0b675a2d 100755 --- a/scripts/test-verify-schema-v3-only.sh +++ b/scripts/test-verify-schema-v3-only.sh @@ -581,9 +581,15 @@ grep -Fq 'export PYTHONDONTWRITEBYTECODE=1' "$project_root/scripts/verify-schema || fail "release wrapper does not disable Python bytecode" release_plan="$($gate_bash "$project_root/scripts/verify-schema-v3-only-release.sh" --dry-run)" first_command="$(printf '%s\n' "$release_plan" | sed -n '1p')" +user_config_command="$(printf '%s\n' "$release_plan" | sed -n '2p')" +global_config_command="$(printf '%s\n' "$release_plan" | sed -n '3p')" bootstrap_command="$(printf '%s\n' "$release_plan" | sed -n '4p')" [[ "$first_command" == 'export PYTHONDONTWRITEBYTECODE=1' ]] \ || fail "release dry-run does not print the Python bytecode export" +[[ "$user_config_command" == 'export NPM_CONFIG_USERCONFIG=' ]] \ + || fail "release dry-run does not isolate npm user configuration" +[[ "$global_config_command" == 'export NPM_CONFIG_GLOBALCONFIG=' ]] \ + || fail "release dry-run does not isolate npm global configuration" [[ "$bootstrap_command" == '/bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only' ]] \ || fail "release plan does not bootstrap trust before npm" printf '%s\n' "$release_plan" | grep -Fq '(cd backend && npm ci --ignore-scripts)' \ diff --git a/scripts/verify-schema-v3-only-release.sh b/scripts/verify-schema-v3-only-release.sh index 27f85b6d..385fee5a 100755 --- a/scripts/verify-schema-v3-only-release.sh +++ b/scripts/verify-schema-v3-only-release.sh @@ -3,14 +3,12 @@ # dependencies come from backend/package-lock.json and dist comes from a clean build. set -euo pipefail export PYTHONDONTWRITEBYTECODE=1 -export NPM_CONFIG_USERCONFIG=/dev/null -export NPM_CONFIG_GLOBALCONFIG=/dev/null root="$(cd "$(dirname "$0")/.." && pwd -P)" if [[ ${1:-} == --dry-run ]]; then cat <<'EOF' export PYTHONDONTWRITEBYTECODE=1 -export NPM_CONFIG_USERCONFIG=/dev/null -export NPM_CONFIG_GLOBALCONFIG=/dev/null +export NPM_CONFIG_USERCONFIG= +export NPM_CONFIG_GLOBALCONFIG= /bin/bash scripts/verify-schema-v3-only.sh --bootstrap-trust-only (cd backend && npm ci --ignore-scripts) (cd backend && npm run build) @@ -21,6 +19,13 @@ EOF exit 0 fi [[ $# -eq 0 ]] || { echo "usage: $0 [--dry-run]" >&2; exit 2; } +release_tmp="$(mktemp -d "${TMPDIR:-/tmp}/thoth-v3-release.XXXXXX")" +trap 'rm -rf "$release_tmp"' EXIT HUP INT TERM +: >"$release_tmp/npm-userconfig" +: >"$release_tmp/npm-globalconfig" +chmod 0600 "$release_tmp/npm-userconfig" "$release_tmp/npm-globalconfig" +export NPM_CONFIG_USERCONFIG="$release_tmp/npm-userconfig" +export NPM_CONFIG_GLOBALCONFIG="$release_tmp/npm-globalconfig" /bin/bash "$root/scripts/verify-schema-v3-only.sh" --bootstrap-trust-only (cd "$root/backend" && npm ci --ignore-scripts) (cd "$root/backend" && npm run build)