fix(create): reject non-semver versions in org-template manifests - #2665
Conversation
🚀 Deploying Preview to Cloudflare 🚀Preview URL: https://fix-org-template-version-validation-viteplus-dev.voidzero-docs.workers.dev (commit 481b6f5)This URL reflects your latest Preview deploymentPreview Deployments by commit
|
Registry bridge build (
|
| Package | Version |
|---|---|
vite-plus |
0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a |
@voidzero-dev/vite-plus-core |
0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a |
Install the Vite+ CLI built from this commit, then migrate a project:
# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install.sh | VP_PR_VERSION=2665 VP_LEGACY_INSTALLER_URL=https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install-legacy.sh bash# Windows (PowerShell)
$env:VP_PR_VERSION="2665"; $env:VP_LEGACY_INSTALLER_URL="https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install-legacy.ps1"; irm https://raw.githubusercontent.com/voidzero-dev/vite-plus/0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a/packages/cli/install.ps1 | iexOr download the standalone Windows installer built from this commit:
| Architecture | Installer |
|---|---|
| x64 | vp-setup-x86_64-pc-windows-msvc.exe |
| Arm64 | vp-setup-aarch64-pc-windows-msvc.exe |
GitHub requires you to sign in and downloads each installer as a ZIP artifact. Extract vp-setup.exe, then run it against this preview build:
.\vp-setup.exe --version "0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a" --registry "https://registry-bridge.viteplus.dev/"After installing, upgrade the current project's vite-plus to this test build with:
vp migrateOr point your package manager at the bridge registry https://registry-bridge.viteplus.dev/:
| Package manager | Registry config |
|---|---|
| npm / pnpm / Bun | .npmrc: registry=https://registry-bridge.viteplus.dev/ |
| Yarn (v2+) | .yarnrc.yml: npmRegistryServer: "https://registry-bridge.viteplus.dev/" |
Then pin the build (vite aliases to vite-plus-core; pnpm can use a catalog, npm an overrides entry):
{
"devDependencies": {
"vite-plus": "0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a",
"vite": "npm:@voidzero-dev/vite-plus-core@0.0.0-commit.0e24d6c2139ea8733ee4a1dd70e4a2a1ba8b4a4a"
}
}
🐳 Docker preview imageBuilt from this PR's registry bridge build:
# remove any stale local copy from a previous run, then pull fresh
docker rmi ghcr.io/voidzero-dev/vite-plus:pr-2665 2>/dev/null; docker pull ghcr.io/voidzero-dev/vite-plus:pr-2665Quick check: docker run --rm ghcr.io/voidzero-dev/vite-plus:pr-2665 vp --versionSee docs/guide/docker.md for usage. |
A registry response can point a dist-tag at a non-semver string, and readOrgManifest() copied that value into OrgManifest.version without validation. The version later becomes a path component in the org-template extraction cache (<cache>/<host>/<scope>/create/<version>), where '..' segments in a malformed value place the extraction directory outside the cache root. Validate the resolved version with semver.valid() at resolution time, covering both the dist-tags.latest branch and the pinned dist-tags[requestedVersion] branch, and keep the same containment invariant at the path construction sink.
fe1a99c to
481b6f5
Compare
…in APIs (#2692) `vp env use` now sets each package manager's version independently. This release also adds Oxlint plugin APIs and fixes migration, installation, and template extraction. ### Breaking Changes #### Package-manager overrides Direct package-manager commands no longer use `VP_PACKAGE_MANAGER`. Use the matching version variable in shell profiles, CI jobs, and Dockerfiles: | Previous override for a direct command | New override | | --- | --- | | `VP_PACKAGE_MANAGER=npm@<version>` | `VP_NPM_VERSION=<version>` | | `VP_PACKAGE_MANAGER=pnpm@<version>` | `VP_PNPM_VERSION=<version>` | | `VP_PACKAGE_MANAGER=yarn@<version>` | `VP_YARN_VERSION=<version>` | | `VP_PACKAGE_MANAGER=bun@<version>` | `VP_BUN_VERSION=<version>` | `VP_PACKAGE_MANAGER` still selects the manager and version for `vp install` and related commands. `vp env use pnpm@10` now changes only the direct pnpm commands. To override `vp install`, set `VP_PACKAGE_MANAGER` explicitly. The old `.session-package-manager` file is no longer read or migrated. Run `vp env use` again to create the new session files. Projects that use only project pins or global defaults need no changes. See the [environment guide](https://viteplus.dev/guide/env) ([#2658](#2658), [#2659](#2659)), by @liangmiQwQ. #### Installer preferences `VP_NODE_MANAGER` now controls only Node.js. Existing installations retain saved preferences during upgrades, so `vp upgrade` needs no configuration changes. For scripted installations, set `VP_PM_MANAGER` to apply the same choice to package managers: | Previous combined setting | New combined setting | | --- | --- | | `VP_NODE_MANAGER=no` | `VP_NODE_MANAGER=no VP_PM_MANAGER=no` | | `VP_NODE_MANAGER=yes` | `VP_NODE_MANAGER=yes VP_PM_MANAGER=yes` | Update installer commands in CI jobs and Dockerfiles. Use `VP_NPM_MANAGER`, `VP_PNPM_MANAGER`, `VP_YARN_MANAGER`, or `VP_BUN_MANAGER` for individual preferences. The interactive prompt retains its combined choice. See the [installer variables guide](https://viteplus.dev/guide/installer-env-vars) ([#2681](#2681)), by @liangmiQwQ. #### Vite DevTools Projects that install `@vitejs/devtools` must update its dependency range from `^0.4.0 || ^0.5.0` to `^0.7.1`. Projects without this optional dependency need no changes. This requirement comes with the Vite upgrade listed below. ### Highlights - Installers and `vp upgrade` share setup behavior across platforms, which simplifies maintenance. The installers retain support for older releases ([#2611](#2611)), by @liangmiQwQ. - Custom Oxlint rules can import their APIs from `vite-plus/lint/plugins` and `vite-plus/lint/plugins-dev`. `vp migrate` updates supported existing imports ([#2328](#2328)), by @fengmk2. - `vp install` and `vp add` now honor `--ignore-scripts` for named packages and managed global installations ([#2682](#2682)), by @jong-kyung. - `vp create` rejects malformed registry versions that could place organization template files outside the cache directory ([#2665](#2665)), by @fengmk2. ### Features - The bundled tools update from `vite@8.2.2` to `vite@8.3.0` and from `rolldown@1.2.7` to `rolldown@1.2.8`. They also update from `oxlint@1.81.0` to `oxlint@1.82.0` and from `oxfmt@0.66.0` to `oxfmt@0.67.0`. The new linter and formatter can flag code that passed before. Run `vp fmt` after the upgrade if CI runs `vp check` ([#2670](#2670)), by @fengmk2. ### Fixes & Enhancements - `vp env pin` updates an active local `.nvmrc` and preserves its comments. Use `--target nvmrc` to select this file explicitly ([#2676](#2676)), by @ywenhao. - `vp migrate` reports unsupported ESLint rules that it skips, so users can review the missing checks ([#2689](#2689)), by @yusuke99. - `vp migrate` imports leftover tsdown configuration when a project already uses Vite+ ([#2646](#2646)), by @TheAlexLichter. - `vp migrate` accepts single-line JSON formatter configuration with a final newline ([#2643](#2643)), by @TheAlexLichter. - `vp migrate` avoids a redundant `playwright` dependency when the project already declares `@playwright/test` ([#2637](#2637)), by @yusuke99. - Newly scaffolded local generators honor `--no-interactive` and report missing arguments without prompts. Existing generators need the updated entrypoint ([#2677](#2677)), by @SaKaNa-Y. - `vp upgrade` installs its dependencies correctly when the installation directory is inside a pnpm workspace ([#2644](#2644)), by @fengmk2. - Nested package-manager commands retain the selected Node runtime and package-manager versions ([#2631](#2631)), by @lyzno1. - Built-in tools reuse the Node executable that starts the CLI. Editor lint and format servers work when `node` is absent from `PATH` ([#2673](#2673)), by @fengmk2. - The npm command wrapper enables Node's compile cache before it loads the CLI, which reduces repeated startup work ([#2648](#2648)), by @pablog12. - Package-manager commands suppress pnpm, npm, and supported Yarn update notices. Yarn 4 daily tips are also hidden ([#2649](#2649), [#2650](#2650), [#2651](#2651)), by @fengmk2. - Invalid `package.json` errors include the affected file's path ([#2683](#2683)), by @adamaveray. ### Docs - The README task example uses the supported `env` field ([#2653](#2653)), by @SaKaNa-Y. - Migration guidance tells pnpm users to retain the generated `vite` and `vitest` dependencies ([#2660](#2660)), by @naokihaba. - Lint and format guides explain root configuration and overrides for monorepos. They clarify that nested configuration is not supported ([#2668](#2668)), by @liangmiQwQ. ### Chore - The repository removes unused Babel dependencies and the unused hooks directory setter ([#2634](#2634), [#2647](#2647)), by @jong-kyung. - CLI snapshot tests run across parallel jobs, and the pnpm 11 workspace pack test excludes generated archives ([#2657](#2657), [#2655](#2655)), by @fengmk2. - CI removes the unused Graphite optimization and adds Solid 2 ecosystem coverage ([#2678](#2678), [#2680](#2680)), by @fengmk2. - Release guidance clarifies validation and announcement procedures ([#2633](#2633)), by @fengmk2. - The runtime manager refreshes the signing keys for Node.js release verification ([#2687](#2687)), by @voidzero-guard[bot]. ### Bundled Versions | Tool | Version | Source | | --- | --- | --- | | `vite` | `8.3.0` | [`434e8e9`](vitejs/vite@434e8e9) | | `rolldown` | `1.2.8` | [`9704b56`](rolldown/rolldown@9704b56) | | `tsdown` | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) | | `vitest` | `4.1.11` | [npm](https://npmx.dev/package/vitest/v/4.1.11) | | `oxlint` | `1.82.0` | [npm](https://npmx.dev/package/oxlint/v/1.82.0) | | `oxlint-tsgolint` | `7.0.2001` | [npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) | | `oxfmt` | `0.67.0` | [npm](https://npmx.dev/package/oxfmt/v/0.67.0) | ### Upgrade ```bash vp upgrade ``` ### New Contributors @yusuke99, @pablog12, @SaKaNa-Y, @ywenhao, @adamaveray **Full Changelog**: v0.3.1...v0.3.2 --- Merging this PR will trigger the release workflow. --------- Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com> Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Malformed registry versions can place org-template files outside the cache root.
readOrgManifest()now rejects versions that failsemver.valid(), including targets fromdist-tags.latestand tags that match a requested version.resolveExtractionDir()also checks that the extraction path stays within the cache root. Tests cover invalid versions, path traversal, and valid versions with prerelease or build metadata.