Skip to content

feat: finalize v0.1.1 delivery and security verification - #8

Merged
kevinten10 merged 3 commits into
mainfrom
feat/final-delivery
Oct 9, 2026
Merged

kevinten10 merged 3 commits into
mainfrom
feat/final-delivery

Conversation

@kevinten10

@kevinten10 kevinten10 commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Final public delivery: v0.1.1

  • Harden the reference HTTP boundary: validate authority/listening port, Origin and fallback Referer, Fetch Metadata, JSON media types, malformed paths, and exact routes including empty/trailing components. Reject before mutation and use generic unexpected-error responses.
  • Fix Local Provider special-file writes/listings and process-group cancellation after the group leader exits. Check opened write descriptors before truncation. Preserve the explicit unsafe/host-permission boundary.
  • Test the actual archive as an independent consumer: isolated install, strict TypeScript example compilation, installed CLI binary, SDK lifecycle/files/commands/SSE, recreation/fencing, startup denial cleanup, and graceful shutdown cleanup.
  • Expand credential/history detection while withholding matched values from scanner output; add synthetic scanner regressions. Move filesystem fixtures into unique task-owned temporary directories.
  • Coordinate Vitest/coverage 5.0.3 updates (supersedes build(deps-dev): bump vitest from 5.0.2 to 5.0.3 in the development-tooling group across 1 directory #7), align package/OpenAPI/reference Provider versions, keep npm publication disabled, and provide bilingual archive guidance plus one acceptance/navigation map.

Provenance and scope

Changes are independently explained by this repository's public lifecycle/file/HTTP contracts, public OWASP origin/media-type guidance, and general POSIX process/file semantics. New fixtures are synthetic. No private repositories, unpublished APIs, real cloud accounts, customer data, or production responses were used.

Cloud/container/Kubernetes Providers, hosted multi-tenancy, strong isolation, durable stores, PTY and snapshots remain candidate RFC extensions, not claims of this delivery. No production deployment or npm registry publication is included. Existing v0.1.0 is preserved.

Verification

Fresh local verification at 88ebf8e0b458eb8a7788cefcc8f30b88ba257e19 (2026-10-09):

  • pnpm check passed: 9 files, 147 tests in both normal and coverage runs; formatting, lint, typecheck, documentation, build, coverage, installed package verification, and all-dependency high-severity audit (no known vulnerabilities).
  • Coverage: 89.92% statements, 85.46% branches, 93.56% functions, 92.21% lines.
  • Actual package verification: 75 entries, strict TypeScript example/types, installed CLI binary, SDK, SSE, startup/shutdown resource cleanup.
  • Navigation validator: 18 managed documents and 46 local links passed. A separate cold-start audit found one stale historical pointer, fixed and rechecked from a fresh context without remaining version/history contradiction.
  • Five diagram SHA-256 hashes match the public source register.
  • pnpm sanitize passed against the candidate worktree and complete available Git history, including image metadata checks. Scanner regression tests confirm detected values are not printed.
  • Independent staging scan: four soft matches, all reviewed. api_key: synthetic is a variable used to generate a deliberately fake temporary regression fixture, not a credential value; fixture@example.test is a reserved synthetic identity; two 10.33.0 matches are the public pnpm version, not private network addresses. No actual credential, dangerous-file, organization-fingerprint, or private-document hit.

CI follow-up (verified)

Initial Node.js 22/24 CI failed six scanner regressions. A restricted-PATH local reproduction confirmed that the old scanner swallowed missing rg errors and incorrectly returned a clean result.

Follow-up 3530cad5992b3327bbd3e70df856029ee659684a replaces that dependency with a self-contained Node.js scanner, preserves value-withholding, and fails closed on root/history errors. Nine scanner regressions pass, including missing-ripgrep and unreadable-root/history cases.

An initial full local follow-up passed 146 normal tests but failed a coverage happy-path command using a one-second test fixture deadline. Commit 88ebf8e0b458eb8a7788cefcc8f30b88ba257e19 separates happy-path startup headroom from deadline assertions: a five-second fixture budget, the existing explicit 20ms timeout test, and a new configured-default 20ms timeout test. Product timeout logic and coverage thresholds are unchanged. The fresh full 147-test check and source/history scan both pass. No failed candidate will be merged or released.

Fresh Node.js 22/24 CI passed at exact head 88ebf8e0b458eb8a7788cefcc8f30b88ba257e19; both required checks completed successfully and GitHub reports the PR clean. The release archive and checksums will be published only from the exact merged main commit, then read back.

@kevinten10
kevinten10 merged commit 6e2744b into main Oct 9, 2026
2 checks passed
@kevinten10

Copy link
Copy Markdown
Member Author

Delivery closed: v0.1.1 is published from exact merged main 6e2744b. PR and main Node.js 22/24 CI passed, with 147 tests in ordinary and coverage runs. The actual archive and downloaded release both passed independent consumer verification; downloaded assets matched byte-for-byte and SHA-256 checks passed. Source/history/media and independent extracted-distribution scans passed with no blocking findings. Release: https://github.com/capa-cloud/sandbox-runtime-api/releases/tag/v0.1.1. Local Provider remains unsafe and development-only; no cloud deployment or npm registry publication.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant