Repository navigation
Rename diff-viewer package to webviews and pin TanStack Router #5426
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -5587,7 +5587,7 @@ extension CMUXCLI { | |
| try FileManager.default.createDirectory(at: targetDirectory, withIntermediateDirectories: true) | ||
|
|
||
| let appSourceDirectory = try diffViewerBundledAppAssetDirectory(nextTo: sourceDirectory) | ||
| let appAssetDirectoryName = "cmux-diff-viewer-app" | ||
| let appAssetDirectoryName = "cmux-webviews-app" | ||
| let targetAppDirectory = viewerURL.deletingLastPathComponent() | ||
| .appendingPathComponent("assets", isDirectory: true) | ||
| .appendingPathComponent(appAssetDirectoryName, isDirectory: true) | ||
|
|
@@ -5626,7 +5626,7 @@ extension CMUXCLI { | |
| private func diffViewerBundledAppAssetDirectory(nextTo sourceDirectory: URL) throws -> URL { | ||
| let appDirectory = sourceDirectory | ||
| .deletingLastPathComponent() | ||
| .appendingPathComponent("diff-viewer-app", isDirectory: true) | ||
| .appendingPathComponent("webviews-app", isDirectory: true) | ||
|
Comment on lines
5627
to
+5629
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When the Swift CLI tests build their temporary fixture resources, Useful? React with 👍 / 👎. |
||
| .standardizedFileURL | ||
| let entry = appDirectory.appendingPathComponent("main.mjs", isDirectory: false) | ||
| var isDirectory: ObjCBool = false | ||
|
|
||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,21 +1,23 @@ | ||
| { | ||
| "name": "@cmux/diff-viewer", | ||
| "name": "@cmux/webviews", | ||
| "version": "0.1.0", | ||
| "private": true, | ||
| "type": "module", | ||
| "scripts": { | ||
| "build": "bun run typecheck && vite build", | ||
| "build": "bun run verify:tanstack-router && bun run typecheck && vite build", | ||
| "lint": "oxlint . --react-plugin --jsx-a11y-plugin --import-plugin", | ||
| "lint:ci": "oxlint . --react-plugin --jsx-a11y-plugin --import-plugin --deny-warnings", | ||
| "lint:fix": "oxlint . --react-plugin --jsx-a11y-plugin --import-plugin --fix", | ||
| "test": "bun test", | ||
| "typecheck": "tsc --noEmit", | ||
| "verify:tanstack-router": "node scripts/verify-tanstack-router-security.mjs", | ||
| "react-doctor": "react-doctor . --full --no-score --fail-on none", | ||
| "react-doctor:ci": "react-doctor . --full --no-score --fail-on error" | ||
| }, | ||
| "dependencies": { | ||
| "@pierre/diffs": "1.2.7", | ||
| "@pierre/trees": "1.0.0-beta.4", | ||
| "@tanstack/react-router": "1.170.11", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time! |
||
| "@vitejs/plugin-react": "^5.1.2", | ||
| "react": "19.2.3", | ||
| "react-dom": "19.2.3", | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,79 @@ | ||
| import { readFileSync } from "node:fs"; | ||
|
|
||
| const expectedDependencyVersion = "1.170.11"; | ||
| const expectedLockEntries = new Map([ | ||
| ["@tanstack/history", { | ||
| version: "1.162.0", | ||
| integrity: "sha512-79pf/RkhteYZTRgcR4F9kbk84P2N8rugQJswxfIqovlbRiT3yI7eBE+5QorIrZaOKktsgzRlXh1l/du/xpl4iA==", | ||
| }], | ||
| ["@tanstack/react-router", { | ||
| version: "1.170.11", | ||
| integrity: "sha512-gP2vzdyaI8Ow/Uz/MRPfK2wN09YwRI0Y/oF74Wuy9R3KmjbfJv2tLrkM+Onu1xWklSn3ugZarMPJXRE0kzrJTA==", | ||
| }], | ||
| ["@tanstack/react-store", { | ||
| version: "0.9.3", | ||
| integrity: "sha512-y2iHd/N9OkoQbFJLUX1T9vbc2O9tjH0pQRgTcx1/Nz4IlwLvkgpuglXUx+mXt0g5ZDFrEeDnONPqkbfxXJKwRg==", | ||
| }], | ||
| ["@tanstack/router-core", { | ||
| version: "1.171.9", | ||
| integrity: "sha512-QM5ZwLT9c5ZcTJW0QQZRRIBC4qjImUyUCXCVyuYVOF9xr76XLsJSX4F2dOxr9VptAv+W+TkWNOYdX8VaO9kdgA==", | ||
| }], | ||
| ["@tanstack/store", { | ||
| version: "0.9.3", | ||
| integrity: "sha512-8reSzl/qGWGGVKhBoxXPMWzATSbZLZFWhwBAFO9NAyp0TxzfBP0mIrGb8CP8KrQTmvzXlR/vFPPUrHTLBGyFyw==", | ||
| }], | ||
| ]); | ||
|
|
||
| const compromisedVersions = new Map([ | ||
| ["@tanstack/history", new Set(["1.161.9", "1.161.12"])], | ||
| ["@tanstack/react-router", new Set(["1.169.5", "1.169.8"])], | ||
| ["@tanstack/router-core", new Set(["1.169.5", "1.169.8"])], | ||
|
Comment on lines
+27
to
+30
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When another GHSA-g7cv-rxg3-hmpx-affected TanStack package is added to this lockfile, this guard will still pass for known-malicious versions because the blocklist only includes three packages; the advisory covers many more affected Useful? React with 👍 / 👎. |
||
| ]); | ||
|
|
||
| const packageJSON = JSON.parse(readFileSync(new URL("../package.json", import.meta.url), "utf8")); | ||
| const lockfile = readFileSync(new URL("../bun.lock", import.meta.url), "utf8"); | ||
|
|
||
| const dependencyVersion = packageJSON.dependencies?.["@tanstack/react-router"]; | ||
| if (dependencyVersion !== expectedDependencyVersion) { | ||
| fail(`@tanstack/react-router must be exact-pinned to ${expectedDependencyVersion}, found ${dependencyVersion ?? "missing"}`); | ||
| } | ||
|
|
||
| const lockEntries = parseTanstackLockEntries(lockfile); | ||
| for (const [name, expected] of expectedLockEntries) { | ||
| const actual = lockEntries.get(name); | ||
| if (!actual) { | ||
| fail(`bun.lock is missing ${name}`); | ||
| } | ||
| if (actual.version !== expected.version) { | ||
| fail(`${name} must resolve to ${expected.version}, found ${actual.version}`); | ||
| } | ||
| if (actual.integrity !== expected.integrity) { | ||
| fail(`${name}@${expected.version} integrity changed`); | ||
| } | ||
| } | ||
|
|
||
| for (const [name, actual] of lockEntries) { | ||
| const badVersions = compromisedVersions.get(name); | ||
| if (badVersions?.has(actual.version)) { | ||
| fail(`${name}@${actual.version} is blocked by GHSA-g7cv-rxg3-hmpx`); | ||
| } | ||
| } | ||
|
|
||
| console.log(`Verified @tanstack/react-router ${expectedDependencyVersion} and TanStack lockfile entries.`); | ||
|
|
||
| function parseTanstackLockEntries(text) { | ||
| const entries = new Map(); | ||
| const linePattern = /^\s+"(@tanstack\/[^"]+)": \["@tanstack\/[^@"]+@([^"]+)",.*"(sha512-[^"]+)"\],?$/gm; | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When Bun has to keep a second copy of a package for a specific dependency, this lockfile format can use prefixed keys like Useful? React with 👍 / 👎. |
||
| for (const match of text.matchAll(linePattern)) { | ||
| entries.set(match[1], { | ||
| version: match[2], | ||
| integrity: match[3], | ||
| }); | ||
| } | ||
| return entries; | ||
| } | ||
|
Comment on lines
+64
to
+74
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time! |
||
|
|
||
| function fail(message) { | ||
| console.error(message); | ||
| process.exit(1); | ||
| } | ||
Uh oh!
There was an error while loading. Please reload this page.