Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/safe-tags-add.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@astrojs/internal-helpers': patch
'astro': patch
'create-astro': patch
---

Allows Astro CLI commands to install tagged package versions
17 changes: 13 additions & 4 deletions packages/internal-helpers/src/cli.ts
Original file line number Diff line number Diff line change
Expand Up @@ -27,19 +27,28 @@ export function validatePackageName(packageName: string): boolean {
}

/**
* Validates a package name and throws an error if invalid.
* Validates a package name with an optional tag or version and throws an error if invalid.
*
* @param packageName - The package name to validate
* @throws {Error} If the package name is invalid
* @param packageName - The package name and optional tag or version to validate
* @throws {Error} If the package name, tag, or version is invalid
*
* @example
* ```ts
* assertValidPackageName('react'); // OK
* assertValidPackageName('react@latest'); // OK
* assertValidPackageName('react; whoami'); // throws Error
* ```
*/
export function assertValidPackageName(packageName: string): asserts packageName is string {
if (!validatePackageName(packageName)) {
const tagSeparator = packageName.lastIndexOf('@');
const hasTag = tagSeparator > 0;
const untaggedPackageName = hasTag ? packageName.slice(0, tagSeparator) : packageName;
const tag = hasTag ? packageName.slice(tagSeparator + 1) : undefined;

if (
!validatePackageName(untaggedPackageName) ||
(tag !== undefined && !validatePackageName(tag))
) {
throw new Error(
`Invalid package name "${packageName}". Package names must follow npm naming rules: ` +
`lowercase letters, numbers, hyphens, underscores, and dots. ` +
Expand Down
19 changes: 19 additions & 0 deletions packages/internal-helpers/test/cli.test.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
import assert from 'node:assert/strict';
import { describe, it } from 'node:test';
import { assertValidPackageName } from '../src/cli.ts';

describe('assertValidPackageName', () => {
it('accepts package names with safe tags and versions', () => {
assert.doesNotThrow(() => assertValidPackageName('react@latest'));
assert.doesNotThrow(() => assertValidPackageName('@astrojs/react@latest'));
assert.doesNotThrow(() => assertValidPackageName('@astrojs/react@5.0.0-beta.1'));
});

it('rejects unsafe or malformed package specifiers', () => {
assert.throws(() => assertValidPackageName('react;whoami@latest'));
assert.throws(() => assertValidPackageName('react@latest;whoami'));
assert.throws(() => assertValidPackageName('react@$(whoami)'));
assert.throws(() => assertValidPackageName('react@latest@next'));
assert.throws(() => assertValidPackageName('@astrojs/react@'));
});
});
Loading