Skip to content

Ci/build pipelines - #664

Merged
Mikey-222 merged 6 commits into
Hel-Phone:mainfrom
Petrelid:ci/build-pipelines
Sep 27, 2026
Merged

Mikey-222 merged 6 commits into
Hel-Phone:mainfrom
Petrelid:ci/build-pipelines

Conversation

@Petrelid

Copy link
Copy Markdown
Contributor

Summary

  1. Build pipeline egress monitor (9c61c44)
    monitor-build-egress.sh blocks unauthorized network egress during builds (allowlisted hosts only); wired into package.json, server/package.json, and render.yaml build steps, with tests.
  2. Automated API drift & breaking-change analyzer (05bc5e3)
    scripts/detect-api-drift.js diffs public API surfaces against checked-in baselines (npm, Cargo crates, TS declaration files), flags unreviewed breaking changes, and gates CI via a new api-drift-guard job. 43 tests, both security:api-drift* scripts pass RC=0.
  3. Browser sandbox isolation for Web Worker scripts (835df40)
    Workers now launch from blob URLs created in a null-origin sandboxed iframe (src/lib/workerSandbox.ts + Vite post-transform plugin), with pre-import storage/DOM lockdown and strict zod message sanitization in both directions; fails open to a same-origin blob worker when opaque origin isn't viable. 47 tests, tsc/eslint/full-suite all at baseline.

Closes #595
Closes #597
Closes #598

- Added `monitor-build-egress.sh` script to detect and block unauthorized network egress during build processes.
- Updated `package.json` to include new security commands for egress monitoring.
- Modified `render.yaml` to run builds under the egress monitor with appropriate flags.
- Enhanced `server/package.json` to integrate egress monitoring in the build process.
- Cleaned up unused imports in `helpStore.ts`.
- Updated global CSS file with a placeholder comment.
- Added tests for the egress detection functionality, covering various scenarios including unauthorized connections and allowlist extensions.
- Implement tests for signature normalization, version classification, and internal member name checks.
- Add tests for surface diffs, ensuring breaking and additive changes are correctly identified.
- Introduce tests for evaluating drift with various scenarios, including major upgrades and exact pin requirements.
- Create tests for parsing Cargo manifests and checking pinning requirements.
- Include tests for extracting type surfaces from in-memory declaration files and real package installations.
- Establish CLI tests for usage, error handling, and JSON output.
…ling

- Implement tests for in-worker lockdown, ensuring restricted access to storage and globals.
- Validate the boot process and message sanitization for zk and cluster worker schemas.
- Test the creation and behavior of sandboxed workers with both same-origin and opaque iframe transports.
- Ensure proper handling of message transferables and schema validation for inbound and outbound messages.
- Integrate Vite plugin tests to confirm correct worker sandboxing behavior during development.
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@Petrelid Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Mikey-222
Mikey-222 merged commit 62ed8ac into Hel-Phone:main Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants