Skip to content

fix(threatcrush-scan): pin the CLI install spec instead of @latest - #952

Merged
ralyodio merged 2 commits into
masterfrom
fix/threatcrush-pin-spec
Aug 11, 2026
Merged

fix(threatcrush-scan): pin the CLI install spec instead of @latest#952
ralyodio merged 2 commits into
masterfrom
fix/threatcrush-pin-spec

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

The problem

The threatcrush-scan action pack installs the CLI with threatcrushPackageSpec defaulting to @profullstack/threatcrush@latest, and that spec is baked into every consumer's workflow at install time. So a scanner that runs on every PR is an unpinned dependency shared across the whole fleet — one bad publish breaks CI in every repo that installed the pack, simultaneously.

That is not hypothetical. A workspace: protocol slip shipped in @profullstack/threatcrush 0.7.0 and 0.7.1 made npm install fail with EUNSUPPORTEDPROTOCOL, and every @latest consumer's scan errored on it — ~28 repos plus the testbed's own CI — on a registry problem that had nothing to do with their diff. The retry loop in the workflow can't help: a broken publish fails deterministically, not transiently.

The fix

Pin the default install spec to a known-good version (@0.11.0) instead of @latest, and bump the pack 1.1.0 → 1.2.0 so the fleet re-syncs consumers off the unpinned spec.

  • New installs pin automatically.
  • A future bad @latest publish can no longer cascade — consumers are on a version that was checked first.
  • Updating is now a deliberate pack release: bump the pinned default to a reviewed version, and the fleet propagates it. That is the whole point of a centrally-managed pack — deliberate, reviewed rollout rather than "whatever the registry served this morning."

Consumers that want to track a different version still override threatcrushPackageSpec per-repo.

Two files: the pack default + description, and the README's input table.

Follow-up for whoever runs the fleet: existing consumers keep the @latest value baked in until they re-sync to pack 1.2.0 — a fleet re-apply propagates the pin to the ~28 repos already installed.

@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

310 finding(s)

HIGH/CRITICAL: 24 | MEDIUM: 50 | LOW: 236

Severity Rule Location
HIGH secret-generic-api-key packages/affiliates/sovrn/src/index.ts:28
HIGH js-nosql-injection packages/ai/amazon-bedrock/src/index.test.ts:121
HIGH secret-generic-credential packages/ai/amazon-bedrock/src/index.ts:9
HIGH secret-generic-credential packages/ai/amazon-bedrock/src/index.ts:10
HIGH secret-generic-credential packages/ai/amazon-bedrock/src/index.ts:11
HIGH js-host-header-trust packages/bots/wechat/src/index.ts:405
HIGH secret-generic-credential packages/bridges/matrix/src/index.ts:58
HIGH secret-generic-credential packages/bridges/matrix/src/index.ts:59
HIGH secret-generic-credential packages/captcha/captchasolver/src/index.ts:34
HIGH secret-generic-credential packages/cli/src/commands/secrets.ts:176
HIGH secret-generic-credential packages/cloud/linode/src/index.ts:15
HIGH secret-generic-credential packages/observability/sentry/src/index.ts:15
HIGH secret-generic-credential packages/outreach/producthunt/src/index.ts:103
HIGH secret-generic-credential packages/promo/posthog/src/index.ts:23
HIGH secret-generic-credential packages/security/snyk/src/index.ts:26
HIGH secret-generic-credential packages/social/hashnode/src/index.ts:4
HIGH secret-generic-credential packages/social/linkedin/src/index.ts:3
HIGH secret-generic-credential packages/social/linkedin/src/index.ts:4
HIGH secret-generic-credential packages/social/medium/src/index.ts:4
HIGH secret-generic-credential packages/social/snapchat/src/index.ts:5
HIGH secret-generic-credential packages/social/tiktok/src/index.ts:5
HIGH secret-generic-credential packages/targets/registry-ans/src/index.ts:49
HIGH secret-generic-credential sites/sh1pt.com/supabase/config.toml:303
HIGH secret-generic-credential sites/sh1pt.com/supabase/config.toml:335
MEDIUM redos-nested-quantifier packages/actions-fleet-core/src/action-pack/schema.ts:3
MEDIUM insecure-temp-file packages/agent-providers/opencode/src/__tests__/opencode.test.ts:19
MEDIUM insecure-temp-file packages/agent-providers/opencode/src/__tests__/opencode.test.ts:42
MEDIUM insecure-temp-file packages/agent-providers/opencode/src/__tests__/opencode.test.ts:45
MEDIUM insecure-temp-file packages/bridges/signal/src/index.test.ts:92
MEDIUM insecure-temp-file packages/bridges/signal/src/index.test.ts:118
MEDIUM insecure-temp-file packages/cli/src/input.test.ts:84
MEDIUM redos-nested-quantifier packages/core/src/setup-helpers.ts:581
MEDIUM insecure-temp-file packages/core/src/testing/harness.ts:15
MEDIUM insecure-temp-file packages/core/src/testing/harness.ts:16
MEDIUM insecure-temp-file packages/core/src/testing/harness.ts:30
MEDIUM insecure-temp-file packages/core/src/testing/harness.ts:42
MEDIUM insecure-temp-file packages/merch/printful/src/index.test.ts:9
MEDIUM insecure-temp-file packages/merch/printify/src/index.test.ts:11
MEDIUM insecure-temp-file packages/policy/src/linter.test.ts:8
MEDIUM redos-nested-quantifier packages/policy/src/rules/bundle-id.ts:3
MEDIUM insecure-temp-file packages/secrets/env-updater/src/index.test.ts:106
MEDIUM insecure-temp-file packages/social/facebook/src/index.test.ts:95
MEDIUM insecure-temp-file packages/social/instagram/src/index.test.ts:177
MEDIUM insecure-temp-file packages/social/pinterest/src/index.test.ts:91
MEDIUM insecure-temp-file packages/social/pinterest/src/index.test.ts:146
MEDIUM insecure-temp-file packages/social/threads/src/index.test.ts:108
MEDIUM insecure-temp-file packages/social/vimeo/src/index.test.ts:137
MEDIUM insecure-temp-file packages/social/x/src/index.test.ts:72
MEDIUM insecure-temp-file packages/social/x/src/index.test.ts:116
MEDIUM insecure-temp-file packages/targets/browser-safari/src/index.test.ts:22

…and 260 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 22b49cb into master Aug 11, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant