Vendor OpenClaw source as Adolf fork baseline
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled

Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11),
free to diverge. Tree copied sans upstream .git; upstream remote added for
future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19.
Preserves docs/ARCHITECTURE.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
This commit is contained in:
2026-07-05 09:36:54 +00:00
parent 3216769225
commit bedb527145
21108 changed files with 6010766 additions and 0 deletions

View File

@@ -0,0 +1,368 @@
// Transitive Manifest Risk Report tests cover transitive manifest risk report script behavior.
import { spawnSync } from "node:child_process";
import path from "node:path";
import { describe, expect, it } from "vitest";
import {
createTransitiveManifestRiskReport,
fetchNpmManifest,
readBoundedNpmRegistryText,
renderTransitiveManifestRiskMarkdownReport,
} from "../../scripts/transitive-manifest-risk-report.mjs";
function runCli(...args: string[]) {
return spawnSync(process.execPath, ["scripts/transitive-manifest-risk-report.mjs", ...args], {
cwd: path.resolve("."),
encoding: "utf8",
});
}
function expectNoNodeStack(stderr: string) {
expect(stderr).not.toContain("Node.js");
expect(stderr).not.toContain("\n at ");
}
describe("transitive-manifest-risk-report", () => {
it("reports CLI argument errors without a Node stack trace", () => {
const unknownArg = runCli("--wat");
expect(unknownArg.status).toBe(1);
expect(unknownArg.stdout).toBe("");
expect(unknownArg.stderr.trim()).toBe("Unsupported argument: --wat");
expectNoNodeStack(unknownArg.stderr);
});
it("reports floating transitive specs, lifecycle scripts, exotic sources, and recently published versions", async () => {
const report = await createTransitiveManifestRiskReport({
packageVersions: [
{ packageName: "parent", version: "1.0.0" },
{ packageName: "tarball-package", version: "https://example.test/pkg.tgz" },
],
now: new Date("2026-05-12T00:00:00Z"),
minimumReleaseAgeMinutes: 2_880,
manifestLoader: async ({ packageName, version }) => {
if (packageName !== "parent" || version !== "1.0.0") {
throw new Error("unexpected manifest request");
}
return {
publishedAt: "2026-05-11T23:00:00Z",
manifest: {
dependencies: {
floating: "^1.2.3",
exact: "2.0.0",
gitdep: "github:owner/repo#main",
},
optionalDependencies: {
optionalFloating: "~3.0.0",
},
scripts: {
install: "node install.js",
},
},
};
},
});
expect(report.byType).toEqual({
"exotic-source": 2,
"floating-transitive-spec": 3,
"lifecycle-script": 1,
"recently-published-version": 1,
});
expect(report.workspaceExcludedFindings).toEqual([]);
expect(report.metadataFailures).toEqual([]);
});
it("uses pnpm minimum release age exclusions for recently published versions", async () => {
const report = await createTransitiveManifestRiskReport({
packageVersions: [
{ packageName: "regular", version: "1.0.0" },
{ packageName: "exact-package", version: "2.0.0" },
{ packageName: "either-version", version: "5.102.1" },
{ packageName: "@scope/native-linux-x64", version: "3.0.0" },
],
now: new Date("2026-05-12T00:00:00Z"),
minimumReleaseAgeMinutes: 2_880,
minimumReleaseAgeExclude: [
"exact-package@2.0.0",
"either-version@4.47.0 || 5.102.1",
"@scope/native-*",
],
manifestLoader: async () => ({
publishedAt: "2026-05-11T23:00:00Z",
manifest: {},
}),
});
expect(report.byType).toEqual({
"recently-published-version": 1,
});
expect(report.workspaceExcludedByType).toEqual({
"recently-published-version": 3,
});
expect(report.findings).toMatchObject([
{
packageName: "regular",
type: "recently-published-version",
},
]);
expect(report.workspaceExcludedFindings).toMatchObject([
{
packageName: "@scope/native-linux-x64",
type: "recently-published-version",
workspaceExcluded: true,
workspaceExclusion: "@scope/native-*",
},
{
packageName: "either-version",
type: "recently-published-version",
workspaceExcluded: true,
workspaceExclusion: "either-version@4.47.0 || 5.102.1",
},
{
packageName: "exact-package",
type: "recently-published-version",
workspaceExcluded: true,
workspaceExclusion: "exact-package@2.0.0",
},
]);
const markdown = renderTransitiveManifestRiskMarkdownReport(report);
expect(markdown).toContain(
"## Recently Published Versions Not Covered By Workspace Exclusions",
);
expect(markdown).toContain("## Recently Published Versions Covered By Workspace Exclusions");
expect(markdown).toContain("Workspace minimum release age: 2880 minutes.");
expect(markdown).toContain("`regular@1.0.0`: published 2026-05-11T23:00:00Z");
expect(markdown).toContain(
"`exact-package@2.0.0`: published 2026-05-11T23:00:00Z; workspace exclusion `exact-package@2.0.0`",
);
expect(markdown).not.toContain(
"`regular@1.0.0`: published 2026-05-11T23:00:00Z; minimum release age 2880 minutes",
);
});
it("documents JSON completeness and renders grouped Markdown summaries", async () => {
const report = await createTransitiveManifestRiskReport({
packageVersions: [
{ packageName: "openclaw/plugin-sdk/llm", version: "0.74.0" },
{ packageName: "aaa-package", version: "1.0.0" },
{ packageName: "recent-package", version: "1.0.0" },
],
now: new Date("2026-05-12T00:00:00Z"),
minimumReleaseAgeMinutes: 2_880,
minimumReleaseAgeExclude: ["recent-package@1.0.0"],
manifestLoader: async ({ packageName }) => ({
publishedAt:
packageName === "recent-package" ? "2026-05-11T23:00:00Z" : "2026-04-01T00:00:00Z",
manifest:
packageName === "openclaw/plugin-sdk/llm"
? {
dependencies: {
"@mistralai/mistralai": "^2.2.0",
},
}
: packageName === "recent-package"
? {
dependencies: {
"recent-dependency": "^1.0.0",
},
}
: {
dependencies: {
"aaa-dependency": "^1.0.0",
},
},
}),
});
const markdown = renderTransitiveManifestRiskMarkdownReport(report);
expect(markdown).toContain("# Transitive Manifest Risk Report");
expect(markdown).toContain("## Scope");
expect(markdown).toContain("published package manifests for resolved packages");
expect(markdown).toContain("It is report-only.");
expect(markdown).toContain("Resolved package versions inspected");
expect(markdown).toContain("Reported risk signals");
expect(markdown).toContain("Signals covered by workspace policy exclusions");
expect(markdown).toContain("## Reported Risk Signals By Type");
expect(markdown).toContain("## Signals Covered By Workspace Policy Exclusions");
expect(markdown).toContain("not included in the reported risk signal totals");
expect(markdown).toContain("## Complete Evidence");
expect(markdown).toContain("The complete reported signal list is available in the JSON report");
expect(markdown).toContain("## Published Package Manifests With Risk Findings");
expect(markdown).toContain("`openclaw/plugin-sdk/llm@0.74.0`: 1 manifest finding");
expect(markdown).toContain("`aaa-package@1.0.0`: 1 manifest finding");
expect(markdown).toContain("## Floating Dependency Targets");
expect(markdown).toContain("`@mistralai/mistralai`: 1 declarations");
expect(markdown).toContain("`aaa-dependency`: 1 declarations");
expect(markdown).not.toContain("## Packages With Findings");
expect(markdown).not.toContain("## Finding Details");
expect(markdown).not.toContain("## Notable Findings");
expect(markdown).not.toContain("## Additional Sample Findings");
});
it("fetches full npm packuments for the requested manifest version", async () => {
const fetchCalls: Array<{ url: string; accept: string | null; signal: AbortSignal | null }> =
[];
const manifest = await fetchNpmManifest({
packageName: "@scope/package",
version: "1.0.0",
registryBaseUrl: "https://registry.example.test",
fetchImpl: async (url, init) => {
fetchCalls.push({
url: String(url),
accept: new Headers(init?.headers).get("accept"),
signal: init?.signal instanceof AbortSignal ? init.signal : null,
});
return new Response(
JSON.stringify({
time: {
"1.0.0": "2026-05-12T00:00:00.000Z",
},
versions: {
"1.0.0": {
dependencies: {
exact: "1.2.3",
},
scripts: {
install: "node install.js",
},
},
},
}),
{
status: 200,
},
);
},
});
expect(fetchCalls).toEqual([
{
url: "https://registry.example.test/@scope%2fpackage",
accept: "application/json",
signal: expect.any(AbortSignal),
},
]);
expect(manifest).toEqual({
publishedAt: "2026-05-12T00:00:00.000Z",
manifest: {
dependencies: {
exact: "1.2.3",
},
scripts: {
install: "node install.js",
},
},
});
});
it("cancels stalled npm registry body reads when the request aborts", async () => {
const controller = new AbortController();
let canceled = false;
const response = {
headers: new Headers(),
body: {
getReader() {
return {
read() {
return new Promise<ReadableStreamReadResult<Uint8Array>>(() => {});
},
async cancel() {
canceled = true;
},
releaseLock() {
throw new Error("releaseLock should not run while a read is pending");
},
};
},
},
} as unknown as Response;
const readPromise = readBoundedNpmRegistryText(response, 8, {
signal: controller.signal,
});
controller.abort(new Error("npm registry request timed out"));
await expect(readPromise).rejects.toThrow("npm registry request timed out");
expect(canceled).toBe(true);
});
it("rejects npm registry bodies that exceed the content-length cap", async () => {
let canceled = false;
const response = new Response(
new ReadableStream({
cancel() {
canceled = true;
},
}),
{
headers: {
"content-length": "12",
},
},
);
await expect(readBoundedNpmRegistryText(response, 8)).rejects.toThrow(
"npm registry response exceeded 8 bytes",
);
expect(canceled).toBe(true);
});
it("rejects npm registry bodies that exceed the content-length cap without a body", async () => {
const response = new Response(null, {
headers: {
"content-length": "12",
},
});
await expect(readBoundedNpmRegistryText(response, 8)).rejects.toThrow(
"npm registry response exceeded 8 bytes",
);
});
it("streams non-decimal npm registry content-length values through the body cap", async () => {
const encoder = new TextEncoder();
let readStarted = false;
let canceled = false;
const response = new Response(
new ReadableStream({
pull(controller) {
readStarted = true;
controller.enqueue(encoder.encode("123456789"));
},
cancel() {
canceled = true;
},
}),
{
headers: {
"content-length": "1e3",
},
},
);
await expect(readBoundedNpmRegistryText(response, 8)).rejects.toThrow(
"npm registry response exceeded 8 bytes",
);
expect(readStarted).toBe(true);
expect(canceled).toBe(true);
});
it("rejects npm registry bodies that grow past the stream cap", async () => {
const encoder = new TextEncoder();
const response = new Response(
new ReadableStream({
start(controller) {
controller.enqueue(encoder.encode("1234"));
controller.enqueue(encoder.encode("5678"));
controller.enqueue(encoder.encode("9"));
controller.close();
},
}),
);
await expect(readBoundedNpmRegistryText(response, 8)).rejects.toThrow(
"npm registry response exceeded 8 bytes",
);
});
});