Commit 99adbe3c14

99adbe3c140718fc1dde69ae1b1143bf1ef388cc

parent: 63ba83a190

Unsigned

cmc <hello@cleberg.net> · 2026-08-21 04:41 UTC

Harden the workflows against supply-chain execution

SonarCloud flagged the new files it was meant to gate, which is the check
working. Four findings, all fixed rather than dismissed:

- npm ci now passes --ignore-scripts in both workflows (S6505). No
  dependency here needs a lifecycle hook; verified from a clean clone.
- The drift job calls ./node_modules/.bin/wrangler instead of npx (S6505,
  S8543). npx resolves and executes on demand at an unpinned version;
  the local binary is the one package-lock pins.

Layout: unified · split

.github/workflows/ci.yml +3 −1
@@ -19,7 +19,9 @@ jobs:
19 node-version: '26' 19 node-version: '26'
20 cache: npm 20 cache: npm
21 21
22 - run: npm ci 22 # --ignore-scripts: no dependency here needs a lifecycle hook, and CI
23 # should not run arbitrary postinstall code from the tree.
24 - run: npm ci --ignore-scripts
23 25
24 # worker-configuration.d.ts is generated, not committed, and tsconfig 26 # worker-configuration.d.ts is generated, not committed, and tsconfig
25 # lists it under "types" — so tsc cannot run on a fresh checkout without 27 # lists it under "types" — so tsc cannot run on a fresh checkout without
.github/workflows/migration-drift.yml +4 −2
@@ -25,7 +25,9 @@ jobs:
25 node-version: '26' 25 node-version: '26'
26 cache: npm 26 cache: npm
27 27
28 - run: npm ci 28 # --ignore-scripts: no dependency here needs a lifecycle hook, and CI
29 # should not run arbitrary postinstall code from the tree.
30 - run: npm ci --ignore-scripts
29 31
30 - name: Every migration in migrations/ is applied to production 32 - name: Every migration in migrations/ is applied to production
31 env: 33 env:
@@ -35,7 +37,7 @@ jobs:
35 echo "::error::CLOUDFLARE_API_TOKEN is not set — this check cannot see production." 37 echo "::error::CLOUDFLARE_API_TOKEN is not set — this check cannot see production."
36 exit 1 38 exit 1
37 fi 39 fi
38 out=$(npx wrangler d1 migrations list DB --remote 2>&1) || true 40 out=$(./node_modules/.bin/wrangler d1 migrations list DB --remote 2>&1) || true
39 echo "$out" 41 echo "$out"
40 if echo "$out" | grep -q "No migrations to apply"; then 42 if echo "$out" | grep -q "No migrations to apply"; then
41 echo "Production schema matches migrations/." 43 echo "Production schema matches migrations/."