Skip to content

Repair development tooling audit with unchanged runtime output - #7

Merged
HomenShum merged 1 commit into
mainfrom
codex/nodeagent-development-tools-20260907
Sep 7, 2026
Merged

Repair development tooling audit with unchanged runtime output#7
HomenShum merged 1 commit into
mainfrom
codex/nodeagent-development-tools-20260907

Conversation

@HomenShum

@HomenShum HomenShum commented Sep 7, 2026

Copy link
Copy Markdown
Owner

The existing NodeAgent development installation retained nine advisory entries, including a critical Vitest finding. Update Vitest to 3.2.6, apply an esbuild 0.28.1 override only to tsup, and reconcile the affected development dependencies. Runtime requirements, exports, CLI, templates and test configuration stay unchanged.

The actual local installation passed ordinary npm ci, npm ls, the unchanged npm run check (57 tests in nine files, types, library/Vite build, tours and existing local scenarios), full npm audit with zero findings, and npm pack. Independent review reopened the exact three-owner diff and all native logs. The actual 37-member tar differs only in development package metadata; its other 36 bodies and all nine build outputs match the previously reviewed runtime package. Convex, tsx and tsup resolve the shared esbuild 0.28.1 installation; the Windows binary matches the preserved prior Convex binary.

Convex remains unconfigured and live-provider execution is skipped. Official Omnigent was absent locally; separate npm omniagent probes passed. Historical generated receipts were restored after preserving the new outputs. No browser, human/device, provider, deployment, package-registry publication or full-readiness claim is added. First shared CI passed on exact head f1ed9f0: NodeAgent CI run 34161296266 passed all 57 tests across nine files, types/build and production audit zero; conformance run 34161296806 passed its four contract declarations, and GitGuardian succeeded. Both Actions runs completed on attempt one. The dedicated official Omnigent probe passed through uv; its existing command checks help/run-help only. The separate prepush PATH probe still reports official Omnigent absent, and no provider execution is claimed. Full installed audit zero is separately bound local evidence. The conformance workflow's separate NodeKit installation reported three advisories; those are outside the NodeAgent lock.

Update Vitest to 3.2.6 and scope esbuild 0.28.1 to tsup.
Retain runtime requirements and document actual install/check/package
continuity, full audit zero and the unchanged provider/UI limits.
@HomenShum
HomenShum merged commit 19de748 into main Sep 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant