Skip to content

fix: restore homepage CSP and patch CI security advisories - #8

Merged
sarthakagrawal927 merged 3 commits into
mainfrom
agent/rolepatch3-root-csp-20261006
Oct 6, 2026
Merged

sarthakagrawal927 merged 3 commits into
mainfrom
agent/rolepatch3-root-csp-20261006

Conversation

@sarthakagrawal927

@sarthakagrawal927 sarthakagrawal927 commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

The Astro homepage bypasses Next.js response headers and currently serves without the CSP already configured for /. Restore that exact policy on the static homepage and Worker-wrapped asset responses, preserving directives, cache headers and compression behavior. Production smoke now rejects missing, empty or different policies.

Regression tests exercise identity/gzip/304 responses, unaffected routing and the existing CLI path-with-spaces check. The first full CI attempt exposed a JSDOM Blob fixture problem; importing Node Blob corrected it without weakening the assertions. The second attempt passed all 524 tests in 89 files, then failed on two newly reported dependency advisories.

Address those advisories with same-line patch floors: source-map-js 1.2.2 and proxy-addr 2.0.8. No direct dependencies, scripts or audit exceptions change. pnpm 10.33.2 generated the lockfile on an existing GitHub runner with lifecycle scripts disabled; independent review verified the artifact digest, registry integrity values and scoped dependency graph diff. The temporary helper workflow and manifest were restored exactly; this PR keeps the normal CI workflow unchanged.

Validation: focused Node checks pass; Biome passes. Exact-head normal full quality and production-build CI are required before merge. Mocked bindings are not deployed Cloudflare or browser proof.

Refs #3. The issue remains open for deployed policy acceptance, the mobile Close-control verification owned by the footer work, and remaining capture/privacy requirements.

@sarthakagrawal927 sarthakagrawal927 changed the title fix: preserve CSP on the Astro homepage fix: restore homepage CSP and patch CI security advisories Oct 6, 2026
@sarthakagrawal927
sarthakagrawal927 merged commit 1110236 into main Oct 6, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant