From 94ba3ed34af2aa101761a42c9a511a99882184e9 Mon Sep 17 00:00:00 2001 From: Revopush Date: Sat, 18 Jul 2026 14:33:59 +0300 Subject: [PATCH 1/6] Bump adm-zip from 0.5.16 to 0.6.0 to fix DoS CVE-2026-39244 (REV-54) adm-zip < 0.6.0 allocates Buffer.alloc(declared_uncompressed_size) before CRC validation with no bounds check, so a ~120-byte crafted ZIP declaring ~4GB uncompressed can exhaust memory and crash the process. 0.6.0 bounds allocation to the actual data present. Used only by extractAPK/extractAAB in script/utils/file-utils.ts via extractAllTo, which is unaffected by 0.6.0's extractEntryTo behavior change. Verified: tsc build clean, npm audit clears adm-zip, and a real ~50MB app-release.apk extracts identically (966 entries -> 922 files). Co-Authored-By: Claude Opus 4.8 (1M context) --- package-lock.json | 11 +++++------ package.json | 2 +- 2 files changed, 6 insertions(+), 7 deletions(-) diff --git a/package-lock.json b/package-lock.json index e7a7c27..c97390c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,7 +9,7 @@ "version": "0.0.13", "dependencies": { "@devicefarmer/adbkit-apkreader": "^3.2.4", - "adm-zip": "^0.5.16", + "adm-zip": "^0.6.0", "backslash": "^0.2.0", "bplist-parser": "^0.3.2", "chalk": "^4.1.2", @@ -1288,12 +1288,11 @@ } }, "node_modules/adm-zip": { - "version": "0.5.16", - "resolved": "https://registry.npmjs.org/adm-zip/-/adm-zip-0.5.16.tgz", - "integrity": "sha512-TGw5yVi4saajsSEgz25grObGHEUaDrniwvA2qwSC060KfqGPdglhvPMA2lPIoxs3PQIItj2iag35fONcQqgUaQ==", - "license": "MIT", + "version": "0.6.0", + "resolved": "https://registry.npmjs.org/adm-zip/-/adm-zip-0.6.0.tgz", + "integrity": "sha512-XleryMhbuksdKtofnWZ9Sk+4CUTbms4Mb/EU32SZwToAyZ5RgVos/ki8n+yr0LWHOGKuakbXTuuYNHLQjhddgg==", "engines": { - "node": ">=12.0" + "node": ">=14.0" } }, "node_modules/ajv": { diff --git a/package.json b/package.json index 19cd23b..1c4be98 100644 --- a/package.json +++ b/package.json @@ -24,7 +24,7 @@ ], "dependencies": { "@devicefarmer/adbkit-apkreader": "^3.2.4", - "adm-zip": "^0.5.16", + "adm-zip": "^0.6.0", "backslash": "^0.2.0", "bplist-parser": "^0.3.2", "chalk": "^4.1.2", From f85e286f8ec6ae5d9de40cbf6948c6771dc18e1d Mon Sep 17 00:00:00 2001 From: Revopush Date: Sat, 18 Jul 2026 14:43:22 +0300 Subject: [PATCH 2/6] Add CI workflow with required "check" job for PRs against main The "check" job (npm ci + build) runs on every PR targeting main and is named to satisfy the org-wide required-status-check branch protection rule. Lint runs as a separate informational job (continue-on-error) because the repo currently has pre-existing eslint errors. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/CI.yaml | 49 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 .github/workflows/CI.yaml diff --git a/.github/workflows/CI.yaml b/.github/workflows/CI.yaml new file mode 100644 index 0000000..28f90fe --- /dev/null +++ b/.github/workflows/CI.yaml @@ -0,0 +1,49 @@ +name: CI + +on: + pull_request: + branches: [main] + +jobs: + # Required status check for merging into main (org-wide branch protection + # matches on the job name "check"). + check: + name: check + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: 20.19.0 + cache: npm + + - name: Install dependencies + run: npm ci + + - name: Build + run: npm run build + + # Informational only — not required for merge (repo has pre-existing lint + # errors). Remove `continue-on-error` once lint is clean to make it enforcing. + lint: + name: lint + runs-on: ubuntu-latest + continue-on-error: true + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: 20.19.0 + cache: npm + + - name: Install dependencies + run: npm ci + + - name: Lint + run: npm run lint From e1220514bc8811a06efd88204c5d5db06fcc621a Mon Sep 17 00:00:00 2001 From: Revopush Date: Sat, 18 Jul 2026 14:52:45 +0300 Subject: [PATCH 3/6] Fix lint via typescript-eslint no-unused-vars; make lint CI-enforcing The base eslint no-unused-vars rule is not TS-aware and falsely flagged every CommandType enum member and the ReleaseHook function-type parameter names. Switch to @typescript-eslint/no-unused-vars (plugin already installed), which correctly treats enum members and type-position parameters as used, and add ^_ ignore patterns for intentionally-unused vars/args. Also fix the one genuine issue it left: != -> !== in debug.ts (eqeqeq), and drop continue-on-error from the lint CI job now that lint is clean. Co-Authored-By: Claude Opus 4.8 (1M context) --- .eslintrc.json | 10 +++++++++- .github/workflows/CI.yaml | 3 --- script/commands/debug.ts | 2 +- 3 files changed, 10 insertions(+), 5 deletions(-) diff --git a/.eslintrc.json b/.eslintrc.json index 46328ad..3d0b419 100644 --- a/.eslintrc.json +++ b/.eslintrc.json @@ -5,12 +5,20 @@ "sourceType": "module", "project": "./tsconfig.json" }, + "plugins": ["@typescript-eslint"], "extends": [ ], "rules": { "no-var": "error", "prefer-const": "error", - "no-unused-vars": "error", + "no-unused-vars": "off", + "@typescript-eslint/no-unused-vars": [ + "error", + { + "argsIgnorePattern": "^_", + "varsIgnorePattern": "^_" + } + ], "eqeqeq": "error", "no-eval": "error" } diff --git a/.github/workflows/CI.yaml b/.github/workflows/CI.yaml index 28f90fe..6f24960 100644 --- a/.github/workflows/CI.yaml +++ b/.github/workflows/CI.yaml @@ -26,12 +26,9 @@ jobs: - name: Build run: npm run build - # Informational only — not required for merge (repo has pre-existing lint - # errors). Remove `continue-on-error` once lint is clean to make it enforcing. lint: name: lint runs-on: ubuntu-latest - continue-on-error: true steps: - name: Checkout uses: actions/checkout@v4 diff --git a/script/commands/debug.ts b/script/commands/debug.ts index 0bcc8a1..787bf07 100644 --- a/script/commands/debug.ts +++ b/script/commands/debug.ts @@ -48,7 +48,7 @@ class AndroidDebugPlatform implements IDebugPlatform { private getNumberOfAvailableDevices(): number { const output = childProcess.execSync("adb devices").toString(); const matches = output.match(/\b(device)\b/gim); - if (matches != null) { + if (matches !== null) { return matches.length; } return 0; From 9fd89bbea355bbe3e782c8073cce985e2f313610 Mon Sep 17 00:00:00 2001 From: Revopush Date: Sat, 18 Jul 2026 14:52:45 +0300 Subject: [PATCH 4/6] Fix lint via typescript-eslint no-unused-vars; make lint CI-enforcing The base eslint no-unused-vars rule is not TS-aware and falsely flagged every CommandType enum member and the ReleaseHook function-type parameter names. Switch to @typescript-eslint/no-unused-vars (plugin already installed), which correctly treats enum members and type-position parameters as used, and add ^_ ignore patterns for intentionally-unused vars/args. Also fix the one genuine issue it left: != -> !== in debug.ts (eqeqeq), and drop continue-on-error from the lint CI job now that lint is clean. Co-Authored-By: Claude Opus 4.8 (1M context) --- .eslintrc.json | 10 +++++++++- .github/workflows/CI.yaml | 5 ----- script/commands/debug.ts | 2 +- 3 files changed, 10 insertions(+), 7 deletions(-) diff --git a/.eslintrc.json b/.eslintrc.json index 46328ad..3d0b419 100644 --- a/.eslintrc.json +++ b/.eslintrc.json @@ -5,12 +5,20 @@ "sourceType": "module", "project": "./tsconfig.json" }, + "plugins": ["@typescript-eslint"], "extends": [ ], "rules": { "no-var": "error", "prefer-const": "error", - "no-unused-vars": "error", + "no-unused-vars": "off", + "@typescript-eslint/no-unused-vars": [ + "error", + { + "argsIgnorePattern": "^_", + "varsIgnorePattern": "^_" + } + ], "eqeqeq": "error", "no-eval": "error" } diff --git a/.github/workflows/CI.yaml b/.github/workflows/CI.yaml index 28f90fe..2906537 100644 --- a/.github/workflows/CI.yaml +++ b/.github/workflows/CI.yaml @@ -5,8 +5,6 @@ on: branches: [main] jobs: - # Required status check for merging into main (org-wide branch protection - # matches on the job name "check"). check: name: check runs-on: ubuntu-latest @@ -26,12 +24,9 @@ jobs: - name: Build run: npm run build - # Informational only — not required for merge (repo has pre-existing lint - # errors). Remove `continue-on-error` once lint is clean to make it enforcing. lint: name: lint runs-on: ubuntu-latest - continue-on-error: true steps: - name: Checkout uses: actions/checkout@v4 diff --git a/script/commands/debug.ts b/script/commands/debug.ts index 0bcc8a1..787bf07 100644 --- a/script/commands/debug.ts +++ b/script/commands/debug.ts @@ -48,7 +48,7 @@ class AndroidDebugPlatform implements IDebugPlatform { private getNumberOfAvailableDevices(): number { const output = childProcess.execSync("adb devices").toString(); const matches = output.match(/\b(device)\b/gim); - if (matches != null) { + if (matches !== null) { return matches.length; } return 0; From 87ef5bbe53048c3b23d00770a0db888d385cf45a Mon Sep 17 00:00:00 2001 From: Revopush Date: Sat, 18 Jul 2026 15:00:06 +0300 Subject: [PATCH 5/6] Harden CI workflow with GitHub Actions best practices - Pin actions to full commit SHAs (v7.0.0) instead of mutable tags, with version comments for readability/Dependabot - Add least-privilege top-level permissions (contents: read) - Add concurrency group with cancel-in-progress to drop superseded PR runs - Add timeout-minutes guard and persist-credentials: false on checkout Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/CI.yaml | 25 +++++++++++++++++++++---- 1 file changed, 21 insertions(+), 4 deletions(-) diff --git a/.github/workflows/CI.yaml b/.github/workflows/CI.yaml index 2906537..6df18ec 100644 --- a/.github/workflows/CI.yaml +++ b/.github/workflows/CI.yaml @@ -4,16 +4,30 @@ on: pull_request: branches: [main] +# Least privilege: CI only reads the repository contents. +permissions: + contents: read + +# Cancel superseded runs when a PR is updated, to save CI minutes. +concurrency: + group: ci-${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + jobs: + # Required status check for merging into main (org-wide branch protection + # matches on the job name "check"). check: name: check runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + with: + persist-credentials: false - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 20.19.0 cache: npm @@ -27,12 +41,15 @@ jobs: lint: name: lint runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + with: + persist-credentials: false - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 20.19.0 cache: npm From 050c74174381f3744dbff7d6214de0888842a114 Mon Sep 17 00:00:00 2001 From: Revopush Date: Sat, 18 Jul 2026 15:01:18 +0300 Subject: [PATCH 6/6] Add Dependabot config for GitHub Actions updates Weekly version updates for the SHA-pinned actions in .github/workflows, grouped into a single PR. Dependabot bumps the commit SHA and the accompanying version comment. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/dependabot.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..63938cb --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,18 @@ +version: 2 +updates: + # Keep GitHub Actions (SHA-pinned in .github/workflows) up to date. + # Dependabot bumps the pinned commit SHA and updates the `# vX.Y.Z` comment. + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + commit-message: + prefix: "ci" + labels: + - "dependencies" + - "github-actions" + # Collapse all action bumps into a single PR to reduce noise. + groups: + github-actions: + patterns: + - "*"