mirror of
https://github.com/pnpm/pnpm.git
synced 2026-07-21 13:12:46 -04:00
* chore: upgrade @typescript/native-preview to 7.0.0-dev.20260421.2
- Add explicit `types: ["node"]` to the shared tsconfig because tsgo
20260421 no longer auto-acquires `@types/*` from `node_modules`.
- Refactor test files to explicitly import jest globals (`describe`,
`it`, `test`, `expect`, `beforeEach`, etc.) from `@jest/globals`
instead of relying on `@types/jest` ambient declarations. Under the
new tsgo build, `import { jest } from '@jest/globals'` shadows the
ambient `jest` namespace, breaking `@types/jest`'s `declare var
describe: jest.Describe;` globals.
- Add `@jest/globals` to each package's devDependencies where tests
now import from it, and add `@types/node` to packages that need it
but were relying on hoisted resolution.
- Replace `fail()` calls with `throw new Error(...)` since `fail` is
no longer globally available.
* chore: fix remaining tsgo type-strictness errors
- Strip `as <PnpmType>` casts on objects passed to toMatchObject /
toStrictEqual / toEqual; @jest/globals rejects the typed objects
(which include AsymmetricMatchers) vs. the repo-specific type.
- Type `jest.fn<...>()` explicitly where the mock's signature matters
for toHaveBeenCalledWith.
- Replace `beforeEach(() => X)` with `beforeEach(() => { X })` so the
return value is void, as the stricter jest typing requires.
- Use `expect.objectContaining({...})` in one place where the full
expected object triggered stricter type resolution.
- Cast `prompt.mock.calls` arg through `as unknown as Record<...>[]`
for patch.test.ts's nested-array matchers.
- Fix off-by-one `<reference path>` in pnpm/test/getConfig.test.ts
that only surfaced now.
- Move `@jest/globals` from devDependencies to dependencies in the
two `__utils__` packages that import it from `src/`.
- Clean up unused imports from the @jest/globals migration.
* chore: address Copilot review on #11332
- Move misplaced `@jest/globals` imports to the top import block in
checkEngine, run.ts, and workspace/root-finder tests where the
script dropped them below executable code.
- Replace `try { await x(); throw new Error('should have thrown') } catch`
in bins/linker, lockfile/fs, and resolving/local-resolver tests with
`await expect(x()).rejects.toMatchObject({...})`. The old pattern
swallowed an unrelated `throw` if the under-test call silently
succeeded, which would fail on the catch-block assertion with a
misleading message.
171 lines
3.6 KiB
TypeScript
171 lines
3.6 KiB
TypeScript
import path from 'node:path'
|
|
|
|
import { expect, test } from '@jest/globals'
|
|
import { getBinsFromPackageManifest } from '@pnpm/bins.resolver'
|
|
|
|
test('getBinsFromPackageManifest()', async () => {
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
bin: 'one-bin',
|
|
name: 'one-bin',
|
|
version: '1.0.0',
|
|
}, process.cwd())).toStrictEqual(
|
|
[{
|
|
name: 'one-bin',
|
|
path: path.resolve('one-bin'),
|
|
}]
|
|
)
|
|
})
|
|
|
|
test('getBinsFromPackageManifest() should allow $ as command name', async () => {
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
bin: {
|
|
$: './undollar.js',
|
|
},
|
|
name: 'undollar',
|
|
version: '1.0.0',
|
|
}, process.cwd())).toStrictEqual(
|
|
[{
|
|
name: '$',
|
|
path: path.resolve('undollar.js'),
|
|
}]
|
|
)
|
|
})
|
|
|
|
test('find all the bin files from a bin directory', async () => {
|
|
const fixtures = path.join(import.meta.dirname, 'fixtures')
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
name: 'bin-dir',
|
|
version: '1.0.0',
|
|
|
|
directories: { bin: 'bin-dir' },
|
|
}, fixtures)).toStrictEqual(
|
|
[
|
|
{
|
|
name: 'rootBin.js',
|
|
path: path.join(fixtures, 'bin-dir/rootBin.js'),
|
|
},
|
|
{
|
|
name: 'subBin.js',
|
|
path: path.join(fixtures, 'bin-dir/subdir/subBin.js'),
|
|
},
|
|
]
|
|
)
|
|
})
|
|
|
|
test('get bin of scoped package', async () => {
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
bin: 'bin.js',
|
|
name: '@foo/bar',
|
|
version: '1.0.0',
|
|
}, process.cwd())).toStrictEqual(
|
|
[{
|
|
name: 'bar',
|
|
path: path.resolve('bin.js'),
|
|
}]
|
|
)
|
|
})
|
|
|
|
test('skip dangerous bin names', async () => {
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
name: 'foo',
|
|
version: '1.0.0',
|
|
|
|
bin: {
|
|
'../bad': './bad',
|
|
'..\\bad': './bad',
|
|
good: './good',
|
|
'~/bad': './bad',
|
|
},
|
|
}, process.cwd())).toStrictEqual(
|
|
[
|
|
{
|
|
name: 'good',
|
|
path: path.resolve('good'),
|
|
},
|
|
]
|
|
)
|
|
})
|
|
|
|
test('skip dangerous bin locations', async () => {
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
name: 'foo',
|
|
version: '1.0.0',
|
|
|
|
bin: {
|
|
bad: '../bad',
|
|
good: './good',
|
|
},
|
|
}, process.cwd())).toStrictEqual(
|
|
[
|
|
{
|
|
name: 'good',
|
|
path: path.resolve('good'),
|
|
},
|
|
]
|
|
)
|
|
})
|
|
|
|
test('get bin from scoped bin name', async () => {
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
name: '@foo/a',
|
|
version: '1.0.0',
|
|
bin: {
|
|
'@foo/a': './a',
|
|
},
|
|
}, process.cwd())).toStrictEqual(
|
|
[
|
|
{
|
|
name: 'a',
|
|
path: path.resolve('a'),
|
|
},
|
|
]
|
|
)
|
|
})
|
|
|
|
test('skip scoped bin names with path traversal', async () => {
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
name: 'malicious',
|
|
version: '1.0.0',
|
|
bin: {
|
|
'@scope/../../.npmrc': './malicious.js',
|
|
'@scope/../etc/passwd': './evil.js',
|
|
'@scope/legit': './good.js',
|
|
},
|
|
}, process.cwd())).toStrictEqual([
|
|
{
|
|
name: 'legit',
|
|
path: path.resolve('good.js'),
|
|
},
|
|
])
|
|
})
|
|
|
|
test('skip directories.bin with path traversal', async () => {
|
|
// Security test: malicious packages can try to escape the package root
|
|
// using directories.bin to chmod files at arbitrary locations
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
name: 'malicious',
|
|
version: '1.0.0',
|
|
directories: {
|
|
bin: '../../../../tmp/target',
|
|
},
|
|
}, process.cwd())).toStrictEqual([])
|
|
|
|
expect(
|
|
await getBinsFromPackageManifest({
|
|
name: 'malicious',
|
|
version: '1.0.0',
|
|
directories: {
|
|
bin: '../../../etc',
|
|
},
|
|
}, process.cwd())).toStrictEqual([])
|
|
})
|