chore(ci): standardize pnpm-only workflows and guard installs - #226
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
📝 WalkthroughWalkthroughAdded a new Dependency Audit GitHub Actions workflow; standardized existing CI workflows to use Changes
Sequence Diagram(s)sequenceDiagram
participant PR as "Pull Request"
participant Runner as "GitHub Actions Runner"
participant Checkout as "actions/checkout"
participant Node as "setup-node (v20)"
participant PNPM as "pnpm/action-setup@v5"
participant Foundry as "foundry-toolchain"
participant Audit as "pnpm-audit action"
participant GH as "GitHub API"
PR->>Runner: trigger (pull_request / workflow_dispatch)
Runner->>Checkout: checkout repo
Runner->>Node: setup Node.js
Runner->>PNPM: setup pnpm
Runner->>Foundry: install Foundry
Runner->>Runner: run `pnpm install` (uses .npmrc frozen-lockfile)
Runner->>Audit: run pnpm-audit (moderate, fails=true)
Audit->>GH: post consolidated comment on PR
Audit-->>Runner: return audit result
Runner-->>PR: update workflow status
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/audit.yml:
- Around line 24-34: Replace the mutable tag references for GitHub Actions with
immutable commit SHAs: update pnpm/action-setup@v5 to
pnpm/action-setup@<commit-sha>, foundry-rs/foundry-toolchain@v1 to
foundry-rs/foundry-toolchain@<commit-sha>, and JamesRobertWiseman/pnpm-audit@v3
to JamesRobertWiseman/pnpm-audit@<commit-sha>; locate the three uses by the
action identifiers (pnpm/action-setup, foundry-rs/foundry-toolchain,
JamesRobertWiseman/pnpm-audit) in the workflow and replace the tag suffixes with
the corresponding full commit SHAs (you can copy the SHA from each action's
GitHub repository commit history).
In `@package.json`:
- Line 64: Prettier failed due to formatting in package.json (missing trailing
newline); run the formatter and commit the fix by running the repository command
(pnpm run prettier) or manually add a newline at end-of-file in package.json and
re-run the formatter, then stage and commit the updated package.json so the CI
Prettier check passes.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 1517e621-a7db-4d99-8199-c13c99180adf
📒 Files selected for processing (11)
.github/workflows/audit.yml.github/workflows/coverage.yml.github/workflows/lint.yml.github/workflows/size.yml.github/workflows/tests-crosschain.yml.github/workflows/tests-fork.yml.github/workflows/tests-proposals.yml.github/workflows/tests-unit.yml.github/workflows/validate-emergency-config.yml.npmrcpackage.json
There was a problem hiding this comment.
🧹 Nitpick comments (1)
package.json (1)
51-72: Overrides correctly address vulnerable transitive dependencies.The
pnpm.overridessyntax is correct and this is the right approach for pinning vulnerable transitive packages.Minor observation: Some override rules are subsumed by others (e.g.,
lodash@<=4.17.23already covers the more specificlodash@>=4.0.0 <=4.17.22rule). If each rule corresponds to a specific CVE for traceability, keeping them separate is fine. Otherwise, consider consolidating:♻️ Optional: Consolidated overrides
"pnpm": { "overrides": { "ajv@<6.14.0": ">=6.14.0", - "brace-expansion@>=2.0.0 <2.0.3": ">=2.0.3", - "brace-expansion@>=2.0.0 <=2.0.1": ">=2.0.2", + "brace-expansion@>=2.0.0 <2.0.3": ">=2.0.3", "cross-spawn@>=7.0.0 <7.0.5": ">=7.0.5", "glob@>=11.0.0 <11.1.0": ">=11.1.0", "js-yaml@>=4.0.0 <4.1.1": ">=4.1.1", - "lodash@<=4.17.23": ">=4.18.0", - "lodash@>=4.0.0 <=4.17.22": ">=4.17.23", - "lodash@>=4.0.0 <=4.17.23": ">=4.18.0", + "lodash@<=4.17.23": ">=4.18.0", "markdown-it@>=13.0.0 <14.1.1": ">=14.1.1", - "minimatch@>=10.0.0 <10.2.1": ">=10.2.1", "minimatch@>=10.0.0 <10.2.3": ">=10.2.3", - "minimatch@>=5.0.0 <5.1.7": ">=5.1.7", "minimatch@>=5.0.0 <5.1.8": ">=5.1.8", "picomatch@<2.3.2": ">=2.3.2", "semver@>=7.0.0 <7.5.2": ">=7.5.2", - "smol-toml@<1.6.1": ">=1.6.1", - "smol-toml@<=1.3.0": ">=1.3.1" + "smol-toml@<1.6.1": ">=1.6.1" } }🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@package.json` around lines 51 - 72, The pnpm.overrides block works but contains overlapping rules that can be consolidated to reduce redundancy; review keys like "lodash@<=4.17.23", "lodash@>=4.0.0 <=4.17.22", and "lodash@>=4.0.0 <=4.17.23" (and similar pairs for "brace-expansion", "minimatch", "smol-toml", etc.) and collapse overlapping ranges into the broadest single rule (e.g., keep "lodash@<=4.17.23" and remove the subsumed narrower entries) unless each distinct override must be retained for CVE traceability—if you must keep them for auditing, add a comment documenting the CVE mapping next to each rule instead of duplicating ranges.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@package.json`:
- Around line 51-72: The pnpm.overrides block works but contains overlapping
rules that can be consolidated to reduce redundancy; review keys like
"lodash@<=4.17.23", "lodash@>=4.0.0 <=4.17.22", and "lodash@>=4.0.0 <=4.17.23"
(and similar pairs for "brace-expansion", "minimatch", "smol-toml", etc.) and
collapse overlapping ranges into the broadest single rule (e.g., keep
"lodash@<=4.17.23" and remove the subsumed narrower entries) unless each
distinct override must be retained for CVE traceability—if you must keep them
for auditing, add a comment documenting the CVE mapping next to each rule
instead of duplicating ranges.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 18ef18db-c951-4222-8648-6d5237c00e18
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (1)
package.json
Summary
pnpm/action-setupversion pins, renaming duplicatedrun-cijob ids, and simplifying install steps to rely on repo lockfile policyaudit.ymldependency audit workflow that runs pnpm audit action directly (no package manager detection fallback paths)packageManager/engines.pnpmto pnpm 10.33.0, addingpreinstall: npx only-allow pnpm, and preserving existing npm/yarn guard semanticsSummary by CodeRabbit
New Features
Chores