Skip to content

fix(create): reject non-semver versions in org-template manifests - #2665

Merged
fengmk2 merged 3 commits into
mainfrom
fix/org-template-version-validation
Sep 11, 2026
Merged

fengmk2 merged 3 commits into
mainfrom
fix/org-template-version-validation

Conversation

@fengmk2

@fengmk2 fengmk2 commented Sep 11, 2026

Copy link
Copy Markdown
Member

Malformed registry versions can place org-template files outside the cache root. readOrgManifest() now rejects versions that fail semver.valid(), including targets from dist-tags.latest and tags that match a requested version.

resolveExtractionDir() also checks that the extraction path stays within the cache root. Tests cover invalid versions, path traversal, and valid versions with prerelease or build metadata.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 11, 2026

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://fix-org-template-version-validation-viteplus-dev.voidzero-docs.workers.dev (commit 481b6f5)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://ad70f9b7-viteplus-dev.voidzero-docs.workers.dev 481b6f5 2026-09-11T08:53:25.761Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://c8c0e2f4-viteplus-dev.voidzero-docs.workers.dev fe1a99c 2026-09-11T08:01:37.621Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://6c09a337-viteplus-dev.voidzero-docs.workers.dev cd6f5ca 2026-09-11T07:06:44.683Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://4f1ca19c-viteplus-dev.voidzero-docs.workers.dev 0e24d6c 2026-09-11T04:07:47.759Z Visit the dashboard ↗

@fengmk2 fengmk2 added the preview-build Publish this PR's commits to the registry bridge as preview builds label Sep 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Registry bridge build (0e24d6c)

This commit build is published to the registry bridge, which serves these as ordinary npm versions (every other package proxies to npmjs):

Package Version
vite-plus 0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a
@voidzero-dev/vite-plus-core 0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a

Install the Vite+ CLI built from this commit, then migrate a project:

# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install.sh | VP_PR_VERSION=2665 VP_LEGACY_INSTALLER_URL=https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install-legacy.sh bash
# Windows (PowerShell)
$env:VP_PR_VERSION="2665"; $env:VP_LEGACY_INSTALLER_URL="https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install-legacy.ps1"; irm https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install.ps1 | iex

Or download the standalone Windows installer built from this commit:

Architecture Installer
x64 vp-setup-x86_64-pc-windows-msvc.exe
Arm64 vp-setup-aarch64-pc-windows-msvc.exe

GitHub requires you to sign in and downloads each installer as a ZIP artifact. Extract vp-setup.exe, then run it against this preview build:

.\vp-setup.exe --version "0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a" --registry "https://registry-bridge.viteplus.dev/"

After installing, upgrade the current project's vite-plus to this test build with:

vp migrate

Or point your package manager at the bridge registry https://registry-bridge.viteplus.dev/:

Package manager Registry config
npm / pnpm / Bun .npmrc: registry=https://registry-bridge.viteplus.dev/
Yarn (v2+) .yarnrc.yml: npmRegistryServer: "https://registry-bridge.viteplus.dev/"

Then pin the build (vite aliases to vite-plus-core; pnpm can use a catalog, npm an overrides entry):

{
  "devDependencies": {
    "vite-plus": "0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a",
    "vite": "npm:@voidzero-dev/vite-plus-core@0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a"
  }
}

@github-actions

Copy link
Copy Markdown
Contributor

🐳 Docker preview image

Built from this PR's registry bridge build:

Image Compressed size
ghcr.io/voidzero-dev/vite-plus:pr-2665 228MB
# remove any stale local copy from a previous run, then pull fresh
docker rmi ghcr.io/voidzero-dev/vite-plus:pr-2665 2>/dev/null; docker pull ghcr.io/voidzero-dev/vite-plus:pr-2665

Quick check:

docker run --rm ghcr.io/voidzero-dev/vite-plus:pr-2665 vp --version

See docs/guide/docker.md for usage.

@fengmk2 fengmk2 self-assigned this Sep 11, 2026
@fengmk2
fengmk2 marked this pull request as ready for review September 11, 2026 07:41
@fengmk2
fengmk2 requested a review from cpojer September 11, 2026 07:41
@fengmk2 fengmk2 added test: e2e Auto run e2e tests test: install-e2e run vite install e2e test test: create-e2e Run `vp create` e2e tests labels Sep 11, 2026
A registry response can point a dist-tag at a non-semver string, and
readOrgManifest() copied that value into OrgManifest.version without
validation. The version later becomes a path component in the
org-template extraction cache (<cache>/<host>/<scope>/create/<version>),
where '..' segments in a malformed value place the extraction directory
outside the cache root.

Validate the resolved version with semver.valid() at resolution time,
covering both the dist-tags.latest branch and the pinned
dist-tags[requestedVersion] branch, and keep the same containment
invariant at the path construction sink.
@fengmk2
fengmk2 force-pushed the fix/org-template-version-validation branch from fe1a99c to 481b6f5 Compare September 11, 2026 08:52
@fengmk2
fengmk2 merged commit 316dd7b into main Sep 11, 2026
108 checks passed
@fengmk2
fengmk2 deleted the fix/org-template-version-validation branch September 11, 2026 09:08
fengmk2 added a commit that referenced this pull request Sep 14, 2026
…in APIs (#2692)

`vp env use` now sets each package manager's version independently. This
release also adds Oxlint plugin APIs and fixes migration, installation,
and template extraction.

### Breaking Changes

#### Package-manager overrides

Direct package-manager commands no longer use `VP_PACKAGE_MANAGER`. Use
the matching version variable in shell profiles, CI jobs, and
Dockerfiles:

| Previous override for a direct command | New override |
| --- | --- |
| `VP_PACKAGE_MANAGER=npm@<version>` | `VP_NPM_VERSION=<version>` |
| `VP_PACKAGE_MANAGER=pnpm@<version>` | `VP_PNPM_VERSION=<version>` |
| `VP_PACKAGE_MANAGER=yarn@<version>` | `VP_YARN_VERSION=<version>` |
| `VP_PACKAGE_MANAGER=bun@<version>` | `VP_BUN_VERSION=<version>` |

`VP_PACKAGE_MANAGER` still selects the manager and version for `vp
install` and related commands. `vp env use pnpm@10` now changes only the
direct pnpm commands. To override `vp install`, set `VP_PACKAGE_MANAGER`
explicitly.

The old `.session-package-manager` file is no longer read or migrated.
Run `vp env use` again to create the new session files. Projects that
use only project pins or global defaults need no changes. See the
[environment guide](https://viteplus.dev/guide/env)
([#2658](#2658),
[#2659](#2659)), by
@liangmiQwQ.

#### Installer preferences

`VP_NODE_MANAGER` now controls only Node.js. Existing installations
retain saved preferences during upgrades, so `vp upgrade` needs no
configuration changes. For scripted installations, set `VP_PM_MANAGER`
to apply the same choice to package managers:

| Previous combined setting | New combined setting |
| --- | --- |
| `VP_NODE_MANAGER=no` | `VP_NODE_MANAGER=no VP_PM_MANAGER=no` |
| `VP_NODE_MANAGER=yes` | `VP_NODE_MANAGER=yes VP_PM_MANAGER=yes` |

Update installer commands in CI jobs and Dockerfiles. Use
`VP_NPM_MANAGER`, `VP_PNPM_MANAGER`, `VP_YARN_MANAGER`, or
`VP_BUN_MANAGER` for individual preferences. The interactive prompt
retains its combined choice. See the [installer variables
guide](https://viteplus.dev/guide/installer-env-vars)
([#2681](#2681)), by
@liangmiQwQ.

#### Vite DevTools

Projects that install `@vitejs/devtools` must update its dependency
range from `^0.4.0 || ^0.5.0` to `^0.7.1`. Projects without this
optional dependency need no changes. This requirement comes with the
Vite upgrade listed below.

### Highlights

- Installers and `vp upgrade` share setup behavior across platforms,
which simplifies maintenance. The installers retain support for older
releases ([#2611](#2611)),
by @liangmiQwQ.
- Custom Oxlint rules can import their APIs from
`vite-plus/lint/plugins` and `vite-plus/lint/plugins-dev`. `vp migrate`
updates supported existing imports
([#2328](#2328)), by
@fengmk2.
- `vp install` and `vp add` now honor `--ignore-scripts` for named
packages and managed global installations
([#2682](#2682)), by
@jong-kyung.
- `vp create` rejects malformed registry versions that could place
organization template files outside the cache directory
([#2665](#2665)), by
@fengmk2.

### Features

- The bundled tools update from `vite@8.2.2` to `vite@8.3.0` and from
`rolldown@1.2.7` to `rolldown@1.2.8`. They also update from
`oxlint@1.81.0` to `oxlint@1.82.0` and from `oxfmt@0.66.0` to
`oxfmt@0.67.0`. The new linter and formatter can flag code that passed
before. Run `vp fmt` after the upgrade if CI runs `vp check`
([#2670](#2670)), by
@fengmk2.

### Fixes & Enhancements

- `vp env pin` updates an active local `.nvmrc` and preserves its
comments. Use `--target nvmrc` to select this file explicitly
([#2676](#2676)), by
@ywenhao.
- `vp migrate` reports unsupported ESLint rules that it skips, so users
can review the missing checks
([#2689](#2689)), by
@yusuke99.
- `vp migrate` imports leftover tsdown configuration when a project
already uses Vite+
([#2646](#2646)), by
@TheAlexLichter.
- `vp migrate` accepts single-line JSON formatter configuration with a
final newline
([#2643](#2643)), by
@TheAlexLichter.
- `vp migrate` avoids a redundant `playwright` dependency when the
project already declares `@playwright/test`
([#2637](#2637)), by
@yusuke99.
- Newly scaffolded local generators honor `--no-interactive` and report
missing arguments without prompts. Existing generators need the updated
entrypoint
([#2677](#2677)), by
@SaKaNa-Y.
- `vp upgrade` installs its dependencies correctly when the installation
directory is inside a pnpm workspace
([#2644](#2644)), by
@fengmk2.
- Nested package-manager commands retain the selected Node runtime and
package-manager versions
([#2631](#2631)), by
@lyzno1.
- Built-in tools reuse the Node executable that starts the CLI. Editor
lint and format servers work when `node` is absent from `PATH`
([#2673](#2673)), by
@fengmk2.
- The npm command wrapper enables Node's compile cache before it loads
the CLI, which reduces repeated startup work
([#2648](#2648)), by
@pablog12.
- Package-manager commands suppress pnpm, npm, and supported Yarn update
notices. Yarn 4 daily tips are also hidden
([#2649](#2649),
[#2650](#2650),
[#2651](#2651)), by
@fengmk2.
- Invalid `package.json` errors include the affected file's path
([#2683](#2683)), by
@adamaveray.

### Docs

- The README task example uses the supported `env` field
([#2653](#2653)), by
@SaKaNa-Y.
- Migration guidance tells pnpm users to retain the generated `vite` and
`vitest` dependencies
([#2660](#2660)), by
@naokihaba.
- Lint and format guides explain root configuration and overrides for
monorepos. They clarify that nested configuration is not supported
([#2668](#2668)), by
@liangmiQwQ.

### Chore

- The repository removes unused Babel dependencies and the unused hooks
directory setter
([#2634](#2634),
[#2647](#2647)), by
@jong-kyung.
- CLI snapshot tests run across parallel jobs, and the pnpm 11 workspace
pack test excludes generated archives
([#2657](#2657),
[#2655](#2655)), by
@fengmk2.
- CI removes the unused Graphite optimization and adds Solid 2 ecosystem
coverage ([#2678](#2678),
[#2680](#2680)), by
@fengmk2.
- Release guidance clarifies validation and announcement procedures
([#2633](#2633)), by
@fengmk2.
- The runtime manager refreshes the signing keys for Node.js release
verification
([#2687](#2687)), by
@voidzero-guard[bot].

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| `vite` | `8.3.0` |
[`434e8e9`](vitejs/vite@434e8e9)
|
| `rolldown` | `1.2.8` |
[`9704b56`](rolldown/rolldown@9704b56)
|
| `tsdown` | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0)
|
| `vitest` | `4.1.11` | [npm](https://npmx.dev/package/vitest/v/4.1.11)
|
| `oxlint` | `1.82.0` | [npm](https://npmx.dev/package/oxlint/v/1.82.0)
|
| `oxlint-tsgolint` | `7.0.2001` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) |
| `oxfmt` | `0.67.0` | [npm](https://npmx.dev/package/oxfmt/v/0.67.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@yusuke99, @pablog12, @SaKaNa-Y, @ywenhao, @adamaveray

**Full Changelog**:
v0.3.1...v0.3.2

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview-build Publish this PR's commits to the registry bridge as preview builds test: create-e2e Run `vp create` e2e tests test: e2e Auto run e2e tests test: install-e2e run vite install e2e test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants