[22/36] Release 0.8.0 with packaged PDF.js preview - #54
Conversation
031947f to
68d43b4
Compare
1058eef to
774c211
Compare
68d43b4 to
b0c429f
Compare
774c211 to
0aa5e8d
Compare
b0c429f to
2893c65
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring alerts on:
|
0aa5e8d to
a703e12
Compare
6b36c22 to
3ea54d2
Compare
|
Verdict: request changes, on scope and dependency classification rather than code correctness (the code changes verified fine).
Verified correct: the frame-src to worker-src CSP replace targets a string that exists verbatim in basePanel.ts:417 so it isn't a silent no-op, and the Deps verdict: buying pdf.js for PDF rendering is right, nobody should hand-roll that. The classification and the double-commit of its artifacts are the issues. |
|
Re-review (whole-stack pass, per REVIEW_GUIDE.md) Head unchanged since the first review, no reply. All four prior findings stand.
New (low): the Socket bot posted six duplicate high-severity "obfuscated code" warnings on Verdict: changes-needed on the scope/retitle and the vendored-blob dual source. The CSP nonce propagation to the dynamic import is verified only by markup assertions, not a runtime webview test. |
|
@SocketSecurity ignore npm/pdfjs-dist@5.4.624 |
|
The review findings are accepted and resolved.
I did not add a simulated CSP runtime test. This repository has no VS Code webview integration harness, and JSDOM does not enforce CSP. The application-controlled boundary is covered by the existing Validation:
Updated PR #56 → PR #54, PR #54 → PR #64, PR #54 → PR #71, and PR #54 → PR #72 all simulate cleanly. GitHub reports PR #54 and immediate child PR #64 as MERGEABLE/CLEAN, with PR #54’s fresh build and security checks passing. |
|
Response to the second review: these findings are addressed on the current head (05b20d2).
I also validated the complete 37-PR composition with npm run build, npm run compile, all 539 tests, and all 47 demo validations passing. |
Summary
pdfjs-dist@5.4.624build assets during build and packaging; generated media files are not committed.Verification
npm run compilenpm test -- --run— 23 files / 438 testsnpm run buildThis is part 1 of 21 in a stack made with GitButler: