Skip to content

Pin the Yarn bootstrap and add SHA-512 lock checksums - #14703

Merged
Sean McManus (sean-mcmanus) merged 3 commits into
mainfrom
seanmcm/devbox2-wsl/agent102/yarn-bootstrap-and-lock-checksums
Aug 25, 2026
Merged

Pin the Yarn bootstrap and add SHA-512 lock checksums#14703
Sean McManus (sean-mcmanus) merged 3 commits into
mainfrom
seanmcm/devbox2-wsl/agent102/yarn-bootstrap-and-lock-checksums

Conversation

@sean-mcmanus

Copy link
Copy Markdown
Contributor

Summary

Two independent Yarn hardening changes, both using only supported package-manager behavior — no new scripts or custom tooling.

  • Extension/yarn.lock now carries SHA-512 integrity alongside the existing SHA-1 for all 932 entries, produced by Yarn's supported yarn install --update-checksums. Yarn's bundled ssri selects the strongest listed digest, so SHA-512 is the value actually enforced on install.
  • npm run bootstrap now installs Yarn from the already-present but previously unused Extension/.yarn-bootstrap/package-lock.json, instead of re-resolving yarn@1.22.22 from the feed on every run with nothing pinning the result.

This retains only the supported-package-manager portion of #14701, which was closed without merging.

Notes for reviewers

  • The yarn.lock diff is large but entirely mechanical. All 1864 changed lines are integrity values; no package version, resolution URL, or dependency edge changed.
  • The retained SHA-1 is not a downgrade. Yarn 1 writes integrity "sha1-… sha512-…", keeping both. Its bundled ssri picks the strongest algorithm present, so SHA-512 is what gets verified. Verified directly: corrupting one entry's SHA-512 while leaving its SHA-1 correct makes yarn install --frozen-lockfile fail with Integrity check failed.
  • Regenerating this lockfile needs a cold Yarn cache and --force. With a warm tree yarn install --update-checksums reports success Already up-to-date and changes nothing; with a warm cache it upgrades only some entries. A useful completeness check is that the count of integrity "sha1-… sha512-…" lines equals the total integrity line count (932).
  • Extension/.yarn-bootstrap/{package.json,package-lock.json} already existed in the repository but were referenced by nothing. Its single entry keeps its SHA-1 value, which npm accepts.
  • The two commits are separated so the mechanical lockfile churn can be reviewed apart from the two-line bootstrap change.

Validation

  • Clean-tree, cold-cache yarn install --frozen-lockfile succeeds and leaves the lockfile unchanged.
  • SHA-512 enforcement verified by the corruption test described above (exit 1, Integrity check failed).
  • Lockfile generation is reproducible: three independent cold-cache runs produced byte-identical output.
  • Both halves of the new bootstrap:yarn run clean and yield Yarn 1.22.22.
  • yarn verify-yarn-lock passes, yarn test-yarn-lock passes, and git diff --check is clean.

This PR was investigated and created by Copilot with Claude Opus 5 (in VS Code). Any message starting with ✨Copilot: was sent by Copilot.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins the Yarn bootstrap install and strengthens dependency verification with SHA-512 integrity hashes.

Changes:

  • Installs Yarn 1.22.22 using the existing pinned npm lockfile.
  • Adds SHA-512 integrity values to all 932 Yarn lock entries.
  • Documents the revised bootstrap process.

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.

File Description
Extension/package.json Uses the pinned bootstrap package for global Yarn installation.
Extension/yarn.lock Adds SHA-512 checksums alongside SHA-1.
Extension/readme.developer.md Documents pinned Yarn bootstrap behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@sean-mcmanus
Sean McManus (sean-mcmanus) marked this pull request as ready for review August 25, 2026 01:17
@sean-mcmanus
Sean McManus (sean-mcmanus) requested a review from a team as a code owner August 25, 2026 01:17
@sean-mcmanus
Sean McManus (sean-mcmanus) merged commit 3202675 into main Aug 25, 2026
6 checks passed
@sean-mcmanus
Sean McManus (sean-mcmanus) deleted the seanmcm/devbox2-wsl/agent102/yarn-bootstrap-and-lock-checksums branch August 25, 2026 02:59
@github-project-automation github-project-automation Bot moved this from Pull Request to Done in cpptools Aug 25, 2026
Sean McManus (sean-mcmanus) added a commit that referenced this pull request Sep 9, 2026
* Use npm ci in issue workflows (#14702)

* Pin the Yarn bootstrap and add SHA-512 lock checksums (#14703)

* Add SHA-512 checksums to yarn.lock

* Pin the Yarn bootstrap install

* Register LLVM component for LLDB-MI (#14704)

* Add xobjgen to gitignore (for Linux/Mac). (#14707)

* Retry transient Yarn install failures (#14708)

* Ensure the language client is always ready before using it (#14617)

* Update 1.34.0 changelog (#14710)

* Update changelog and version for 1.34.1 (#14714)

* Update clang-tidy checks to 23.1.0 (#14713)

* Use native file type mappings for TypeScript-side classification (#14711)

* Add 1.34.2 changelog (#14722)

* Add 1.34.2 changelog

* Remove ignored network isolation policy (#14728)

* Bump fast-uri from 3.1.5 to 3.1.6 in /ExtensionPack (#14731)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.6.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.6)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump @xmldom/xmldom from 0.8.13 to 0.8.15 in /Extension (#14733)

Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.13 to 0.8.15.
- [Release notes](https://github.com/xmldom/xmldom/releases)
- [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md)
- [Commits](xmldom/xmldom@0.8.13...0.8.15)

---
updated-dependencies:
- dependency-name: "@xmldom/xmldom"
  dependency-version: 0.8.15
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump browserslist from 4.28.1 to 4.28.8 in /Extension (#14732)

Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.1 to 4.28.8.
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](browserslist/browserslist@4.28.1...4.28.8)

---
updated-dependencies:
- dependency-name: browserslist
  dependency-version: 4.28.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Remove unused gulp-sourcemaps dependency (#14729)

* Remove unused gulp-sourcemaps dependency

* Remove orphaned dependency resolutions

* Fix custom configuration provider regression (#14725)

* Restore custom configuration provider checks

* Ignore empty crash report files (#14730)

* Ignore empty crash report files

* Preserve pending crash reads across clients

* Keep crash writing state for pending reports

* Fix fast-uri dependency. (#14735)

* Fix fast-uri dependency.

* Also for Themes.

* Implement session state tracking for "Run and Debug" button when Inte… (#14719)

* Implement session state tracking for "Run and Debug" button when IntelliSense is disabled and add corresponding tests

* Enhance session state tracking for build and debug by updating folder open status and adding tests

* Fix build and debug folder session state tracking

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Sean McManus <seanmcm@microsoft.com>

* Fix #11263: Make Edit Configurations UI fully theme-aware in custom themes (#14692)

* Fix #11263: use theme-aware colors in Edit Configurations UI

* Enhance dropdown styling with theme-aware colors in settings UI

---------

Co-authored-by: Sean McManus <seanmcm@microsoft.com>

* Add processFilter for remote attach process selection (#14684)

* Add processFilter for remote attach process selection

When attaching to a process on a remote target, the process always has
to be selected by hand, even though the launch configuration already
knows which executable it belongs to. A generated configuration cannot
hard-code processId either, because the pid changes on every boot and
on every restart of the service, so the picker is the only option.

Add an optional processFilter regular expression to the cppdbg attach
configuration. When set, it is matched against the label, description
and detail of the remote process list:

  exactly one match  attach to that process directly
  more than one      show the picker with only the matching entries
  no match           show the full picker, as before

All three fields are considered because the item format depends on the
transport: useExtendedRemote reports the user and the full command line
in the label, while pipeTransport reports the process name in the label
and the command line in the detail.

An invalid regular expression is reported instead of being silently
ignored.

This affects remote attach only (pipeTransport and useExtendedRemote);
local attach continues to use program-based matching.

Closes #14682

* Extract remote process filtering into a helper

Move the matching logic out of RemoteAttachPicker into a standalone
function so that it can be unit tested without a VS Code quick pick or
a live connection to a remote target.

No functional change.

* Add unit tests for processFilter matching

Cover empty and non-string filter values, matching against label,
description and detail, multiple matches, an invalid regular
expression, and a regression case ensuring missing fields are not
treated as empty strings.

---------

Co-authored-by: Adrian Freihofer <adrian.freihofer@siemens.com>
Co-authored-by: Sean McManus <seanmcm@microsoft.com>

* Bump the github-actions group with 2 updates (#14738)

Bumps the github-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.7 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@ff2f1c6...cdf488f)

Updates `github/codeql-action/analyze` from 4.37.7 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@ff2f1c6...cdf488f)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Fix localization translation errors (#14737)

* Localization - Translated Strings

* Fix localization translation errors

* Address localization review feedback

* Fix localization review feedback

---------

Co-authored-by: csigs <csigs@users.noreply.github.com>

* Update changelog for 1.34.3 (#14740)

* Update changelog and version for 1.34.4. (#14748)

* Enable PR CI for release and insiders (#14751)

* Fix localization string import (#14743)

* Fix localization string import
* Correct conversion cycle translations

* Add Run and Debug session state tests (#14736)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Bob Brown <bobbrow@users.noreply.github.com>
Co-authored-by: Colen Garoutte-Carson <49173979+Colengms@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Prashant Kumar Rai <prashant.kumar2021@vitbhopal.ac.in>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: afreof <adrian.freihofer@gmail.com>
Co-authored-by: Adrian Freihofer <adrian.freihofer@siemens.com>
Co-authored-by: csigs <csigs@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants