From fdf6e13b01189b929232c3d797802f45a1193b9e Mon Sep 17 00:00:00 2001 From: "@permadeath.com" Date: Wed, 12 Aug 2026 14:29:24 -0400 Subject: [PATCH] build(deps): pin actor-typeahead to an exact version MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit actor-typeahead renders inside the sign-in form, in the popup, with the privileges of an extension page — the highest-leverage third-party surface the extension has, on a 0.x line that can change shape between patch releases. The lockfile already pins what a release installs, since deploy-ext.sh runs npm ci; this covers the other half, so a bare npm install cannot move it without someone deciding to. A test keeps the range exact, because `npm install --save` would quietly write a caret back. --- TODO.md | 8 -------- package-lock.json | 2 +- package.json | 2 +- scripts/dependencies.test.mjs | 21 +++++++++++++++++++++ 4 files changed, 23 insertions(+), 10 deletions(-) create mode 100644 scripts/dependencies.test.mjs diff --git a/TODO.md b/TODO.md index b4da4de..68834d0 100644 --- a/TODO.md +++ b/TODO.md @@ -223,14 +223,6 @@ Nothing runs `npm run check`, `npm test`, `verify:dist` or committer who has them installed and nothing else. Needs a decision about where CI would run for a Tangled-hosted repo before it is worth wiring. -## Pin actor-typeahead exactly - -`actor-typeahead` is at `^0.1.2` — a 0.x web component from a third party that -renders inside the sign-in form, in the popup, with full extension-page -privileges. It is the highest-leverage supply-chain surface in the extension. -The lockfile pins the resolved version today; an exact dependency range would -also stop `npm install` from moving it without a review. - ## Subscriber row: two caps that can hide a face `src/lib/subscribers.ts` answers "who that you follow subscribes here" by diff --git a/package-lock.json b/package-lock.json index 91e549c..2df09c2 100644 --- a/package-lock.json +++ b/package-lock.json @@ -11,7 +11,7 @@ "dependencies": { "@atproto/api": "^0.20.39", "@atproto/oauth-client-browser": "^0.5.3", - "actor-typeahead": "^0.1.2" + "actor-typeahead": "0.1.2" }, "devDependencies": { "@types/chrome": "^0.0.280", diff --git a/package.json b/package.json index 282d525..30a8ca9 100644 --- a/package.json +++ b/package.json @@ -26,7 +26,7 @@ "dependencies": { "@atproto/api": "^0.20.39", "@atproto/oauth-client-browser": "^0.5.3", - "actor-typeahead": "^0.1.2" + "actor-typeahead": "0.1.2" }, "devDependencies": { "@types/chrome": "^0.0.280", diff --git a/scripts/dependencies.test.mjs b/scripts/dependencies.test.mjs new file mode 100644 index 0000000..bcdd38a --- /dev/null +++ b/scripts/dependencies.test.mjs @@ -0,0 +1,21 @@ +import { readFileSync } from 'node:fs' +import { join } from 'node:path' +import { describe, expect, it } from 'vitest' + +const pkg = JSON.parse(readFileSync(join(import.meta.dirname, '..', 'package.json'), 'utf8')) + +describe('runtime dependencies', () => { + /** + * actor-typeahead renders inside the sign-in form, in the popup, with the + * privileges of an extension page — the highest-leverage third-party surface + * the extension has, and a 0.x release line that can change shape between + * patch versions. An exact range means a bare `npm install` cannot move it + * without someone deciding to. + * + * The lockfile already pins what a release installs (`deploy-ext.sh` runs + * `npm ci`); this is the half that covers the development tree. + */ + it('pins actor-typeahead to an exact version', () => { + expect(pkg.dependencies['actor-typeahead']).toMatch(/^\d+\.\d+\.\d+$/) + }) +}) -- 2.51.2