Skip to content

chore(ci): standardize pnpm-only workflows and guard installs - #226

Merged
0xJem merged 5 commits into
developfrom
chore/pnpm-hardening-2026-04-02
Apr 2, 2026
Merged

0xJem merged 5 commits into
developfrom
chore/pnpm-hardening-2026-04-02

Conversation

@0xJem

@0xJem 0xJem commented Apr 2, 2026 •

Copy link
Copy Markdown
Member

Summary

  • switch olympus-v3 CI workflows to pnpm-only setup by removing hardcoded pnpm/action-setup version pins, renaming duplicated run-ci job ids, and simplifying install steps to rely on repo lockfile policy
  • add a dedicated audit.yml dependency audit workflow that runs pnpm audit action directly (no package manager detection fallback paths)
  • harden package manager enforcement in project config by setting packageManager/engines.pnpm to pnpm 10.33.0, adding preinstall: npx only-allow pnpm, and preserving existing npm/yarn guard semantics

Summary by CodeRabbit

  • New Features

    • Added an automated dependency vulnerability audit to CI (runs on PRs and manually).
  • Chores

    • Standardized CI job names and updated CI tooling setup across workflows.
    • Enforced pnpm as the package manager with a preinstall check and stricter lockfile policy.
    • Added dependency override rules to pin safer dependency versions.

@coderabbitai

coderabbitai Bot commented Apr 2, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 38fac2fe-3125-427b-9550-9bcc369d312c

📥 Commits

Reviewing files that changed from the base of the PR and between 29d0a13 and a21e45a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

📝 Walkthrough

Walkthrough

Added a new Dependency Audit GitHub Actions workflow; standardized existing CI workflows to use pnpm/action-setup@v5 and pnpm install (lockfile enforcement moved to .npmrc); pinned pnpm in package.json, added a preinstall guard, and introduced pnpm.overrides.

Changes

Cohort / File(s) Summary
New Dependency Audit Workflow
\.github/workflows/audit.yml
Adds a workflow (on pull_request and workflow_dispatch) that sets up Node.js, pnpm, and Foundry, runs pnpm install, and executes JamesRobertWiseman/pnpm-audit@v3 (severity: moderate, fails: true, single_comment: true).
CI Workflow Updates
\.github/workflows/{coverage.yml,lint.yml,size.yml,tests-crosschain.yml,tests-fork.yml,tests-proposals.yml,tests-unit.yml}, \.github/workflows/validate-emergency-config.yml
Renamed jobs for clarity, upgraded pnpm/action-setup to v5 (removed explicit pnpm version), replaced pnpm install --frozen-lockfile with pnpm install and added comments that .npmrc enforces frozen-lockfile; other steps unchanged.
Package manager / Lockfile Policy
\.npmrc, package.json
.npmrc adds prefer-frozen-lockfile=true and frozen-lockfile=true; package.json gains packageManager: "pnpm@10.33.0", engines.pnpm, scripts.preinstall: "npx only-allow pnpm", and a pnpm.overrides block to pin/override multiple dependency ranges.

Sequence Diagram(s)

sequenceDiagram
  participant PR as "Pull Request"
  participant Runner as "GitHub Actions Runner"
  participant Checkout as "actions/checkout"
  participant Node as "setup-node (v20)"
  participant PNPM as "pnpm/action-setup@v5"
  participant Foundry as "foundry-toolchain"
  participant Audit as "pnpm-audit action"
  participant GH as "GitHub API"

  PR->>Runner: trigger (pull_request / workflow_dispatch)
  Runner->>Checkout: checkout repo
  Runner->>Node: setup Node.js
  Runner->>PNPM: setup pnpm
  Runner->>Foundry: install Foundry
  Runner->>Runner: run `pnpm install` (uses .npmrc frozen-lockfile)
  Runner->>Audit: run pnpm-audit (moderate, fails=true)
  Audit->>GH: post consolidated comment on PR
  Audit-->>Runner: return audit result
  Runner-->>PR: update workflow status
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Poem

🐰 I hopped through workflows, tidy and bright,
pinned pnpm, kept lockfiles snug and tight.
I audited deps with one tidy ping,
left a single comment — hear it sing!
Carrots, commits, and CI delight.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main changes: standardizing pnpm-only workflows and adding install guards, which aligns with all file modifications across CI workflows, package configuration, and dependency audit addition.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/pnpm-hardening-2026-04-02

Comment @coderabbitai help to get the list of available commands and usage tips.

@0xJem 0xJem self-assigned this Apr 2, 2026
@0xJem
0xJem requested a review from a team April 2, 2026 11:38

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/audit.yml:
- Around line 24-34: Replace the mutable tag references for GitHub Actions with
immutable commit SHAs: update pnpm/action-setup@v5 to
pnpm/action-setup@<commit-sha>, foundry-rs/foundry-toolchain@v1 to
foundry-rs/foundry-toolchain@<commit-sha>, and JamesRobertWiseman/pnpm-audit@v3
to JamesRobertWiseman/pnpm-audit@<commit-sha>; locate the three uses by the
action identifiers (pnpm/action-setup, foundry-rs/foundry-toolchain,
JamesRobertWiseman/pnpm-audit) in the workflow and replace the tag suffixes with
the corresponding full commit SHAs (you can copy the SHA from each action's
GitHub repository commit history).

In `@package.json`:
- Line 64: Prettier failed due to formatting in package.json (missing trailing
newline); run the formatter and commit the fix by running the repository command
(pnpm run prettier) or manually add a newline at end-of-file in package.json and
re-run the formatter, then stage and commit the updated package.json so the CI
Prettier check passes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 1517e621-a7db-4d99-8199-c13c99180adf

📥 Commits

Reviewing files that changed from the base of the PR and between abf724f and bbaf51f.

📒 Files selected for processing (11)
  • .github/workflows/audit.yml
  • .github/workflows/coverage.yml
  • .github/workflows/lint.yml
  • .github/workflows/size.yml
  • .github/workflows/tests-crosschain.yml
  • .github/workflows/tests-fork.yml
  • .github/workflows/tests-proposals.yml
  • .github/workflows/tests-unit.yml
  • .github/workflows/validate-emergency-config.yml
  • .npmrc
  • package.json

Comment thread .github/workflows/audit.yml
Comment thread package.json Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
package.json (1)

51-72: Overrides correctly address vulnerable transitive dependencies.

The pnpm.overrides syntax is correct and this is the right approach for pinning vulnerable transitive packages.

Minor observation: Some override rules are subsumed by others (e.g., lodash@<=4.17.23 already covers the more specific lodash@>=4.0.0 <=4.17.22 rule). If each rule corresponds to a specific CVE for traceability, keeping them separate is fine. Otherwise, consider consolidating:

♻️ Optional: Consolidated overrides
 "pnpm": {
     "overrides": {
         "ajv@<6.14.0": ">=6.14.0",
-        "brace-expansion@>=2.0.0 <2.0.3": ">=2.0.3",
-        "brace-expansion@>=2.0.0 <=2.0.1": ">=2.0.2",
+        "brace-expansion@>=2.0.0 <2.0.3": ">=2.0.3",
         "cross-spawn@>=7.0.0 <7.0.5": ">=7.0.5",
         "glob@>=11.0.0 <11.1.0": ">=11.1.0",
         "js-yaml@>=4.0.0 <4.1.1": ">=4.1.1",
-        "lodash@<=4.17.23": ">=4.18.0",
-        "lodash@>=4.0.0 <=4.17.22": ">=4.17.23",
-        "lodash@>=4.0.0 <=4.17.23": ">=4.18.0",
+        "lodash@<=4.17.23": ">=4.18.0",
         "markdown-it@>=13.0.0 <14.1.1": ">=14.1.1",
-        "minimatch@>=10.0.0 <10.2.1": ">=10.2.1",
         "minimatch@>=10.0.0 <10.2.3": ">=10.2.3",
-        "minimatch@>=5.0.0 <5.1.7": ">=5.1.7",
         "minimatch@>=5.0.0 <5.1.8": ">=5.1.8",
         "picomatch@<2.3.2": ">=2.3.2",
         "semver@>=7.0.0 <7.5.2": ">=7.5.2",
-        "smol-toml@<1.6.1": ">=1.6.1",
-        "smol-toml@<=1.3.0": ">=1.3.1"
+        "smol-toml@<1.6.1": ">=1.6.1"
     }
 }
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@package.json` around lines 51 - 72, The pnpm.overrides block works but
contains overlapping rules that can be consolidated to reduce redundancy; review
keys like "lodash@<=4.17.23", "lodash@>=4.0.0 <=4.17.22", and "lodash@>=4.0.0
<=4.17.23" (and similar pairs for "brace-expansion", "minimatch", "smol-toml",
etc.) and collapse overlapping ranges into the broadest single rule (e.g., keep
"lodash@<=4.17.23" and remove the subsumed narrower entries) unless each
distinct override must be retained for CVE traceability—if you must keep them
for auditing, add a comment documenting the CVE mapping next to each rule
instead of duplicating ranges.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@package.json`:
- Around line 51-72: The pnpm.overrides block works but contains overlapping
rules that can be consolidated to reduce redundancy; review keys like
"lodash@<=4.17.23", "lodash@>=4.0.0 <=4.17.22", and "lodash@>=4.0.0 <=4.17.23"
(and similar pairs for "brace-expansion", "minimatch", "smol-toml", etc.) and
collapse overlapping ranges into the broadest single rule (e.g., keep
"lodash@<=4.17.23" and remove the subsumed narrower entries) unless each
distinct override must be retained for CVE traceability—if you must keep them
for auditing, add a comment documenting the CVE mapping next to each rule
instead of duplicating ranges.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 18ef18db-c951-4222-8648-6d5237c00e18

📥 Commits

Reviewing files that changed from the base of the PR and between bbaf51f and baa8fb8.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

@0xJem
0xJem merged commit 5691c54 into develop Apr 2, 2026
12 checks passed
@0xJem
0xJem deleted the chore/pnpm-hardening-2026-04-02 branch April 2, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant