Three findings against the install-script allowlist landed by the HTML/SVG preview PR: 1. Allowlist matched on package name alone, so adding 'esbuild' silently approved every future esbuild postinstall version. Pin each entry to name@version and reject bare names. 2. The script defaulted the allowlist path to the head checkout's .install-script-allowlist, so the same PR that introduced a new postinstall dep could allowlist it in the same diff. Source the allowlist from the BASE ref instead; any head-only entry fails the gate. 3. The security-audit workflow only extracted the BASE package-lock, leaving the allowlist defaulted to the PR checkout. Update the workflow to also extract the BASE allowlist and pass it through --base-allowlist. The existing esbuild entry is now pinned to esbuild@0.21.5 so the gate refuses any future esbuild version that has not been re-eyeballed. |
||
|---|---|---|
| .. | ||
| public | ||
| src | ||
| .gitignore | ||
| .gitkeep | ||
| .install-script-allowlist | ||
| .npmrc | ||
| biome.json | ||
| components.json | ||
| data-designer.openapi (1).yaml | ||
| eslint.config.js | ||
| index.html | ||
| package-lock.json | ||
| package.json | ||
| tsconfig.app.json | ||
| tsconfig.json | ||
| tsconfig.node.json | ||
| vite.config.ts | ||
| vitest.config.ts | ||