Three findings against the install-script allowlist landed by the
HTML/SVG preview PR:
1. Allowlist matched on package name alone, so adding 'esbuild'
silently approved every future esbuild postinstall version. Pin
each entry to name@version and reject bare names.
2. The script defaulted the allowlist path to the head checkout's
.install-script-allowlist, so the same PR that introduced a new
postinstall dep could allowlist it in the same diff. Source the
allowlist from the BASE ref instead; any head-only entry fails
the gate.
3. The security-audit workflow only extracted the BASE package-lock,
leaving the allowlist defaulted to the PR checkout. Update the
workflow to also extract the BASE allowlist and pass it through
--base-allowlist.
The existing esbuild entry is now pinned to esbuild@0.21.5 so the
gate refuses any future esbuild version that has not been
re-eyeballed.