From 0c791e5b76772716b00ad2badbf700e53f1dbfe0 Mon Sep 17 00:00:00 2001 From: tannevaled Date: Sat, 26 Sep 2026 18:33:03 +0200 Subject: [PATCH] esbuildsandbox, one function against one leak Three modules, two cards. The missing one is the security fix, and the card spends its space on the mechanism rather than the API, because the API is one call: a plugin that intercepts every import still leaks, since the bundler expands a glob dynamic import by walking ResolveDir on the real filesystem. Co-Authored-By: Claude Opus 5 --- .github/workflows/docs.yml | 24 ++++++++++++++++++++++++ hugo.toml | 5 +++++ 2 files changed, 29 insertions(+) create mode 100644 .github/workflows/docs.yml diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml new file mode 100644 index 0000000..2300ff5 --- /dev/null +++ b/.github/workflows/docs.yml @@ -0,0 +1,24 @@ +# Does this organisation advertise what it has? +# +# The landing drifts silently: a repository is created, and nothing in any +# repository fails because no page mentions it. esbuildsandbox closes a sandbox +# leak in a dependency, and was on no page of the organisation that found it. +# +# ⛔ NOT `on: [push, pull_request]`: both fire for a branch with a pull request +# open, so every push runs the check twice. +# +# ⛔ It needs NO secret. Listing a public organisation and reading its surfaces +# are public reads, so this runs on github.token. +name: docs + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +jobs: + current: + uses: go-fleettools/fleettools/.github/workflows/docs-current.yml@main diff --git a/hugo.toml b/hugo.toml index d95b451..a01bf8b 100644 --- a/hugo.toml +++ b/hugo.toml @@ -12,6 +12,11 @@ disableKinds = ["taxonomy", "term", "RSS", "sitemap", "404"] type = "lib + cli" blurb = "Fetch a URL → DOM → CSS cascade (var()/@media/dark-mode) → run the page's JavaScript → full box-model layout (flex/grid/tables/position) → paint anti-aliased text, gradients, images and SVG to an image.RGBA / PNG. Pure Go, CGO_ENABLED=0, no Chromium; ships a `render` CLI." badge = true +[[params.repos]] + name = "esbuildsandbox" + role = "One function, against one leak" + type = "lib" + blurb = "A safe ResolveDir for esbuild's pkg/api. A caller bundling untrusted source installs an OnResolve/OnLoad plugin and it looks complete — every import in its own tests goes through it. But the bundler expands a glob dynamic import, import(`./${lang}/index.js`), by walking ResolveDir on the real filesystem through its internal resolver, bypassing the plugin entirely. Whatever that directory is — \"/\" is a common default — is what gets walked, following symlinks. This returns a directory where that walk finds nothing." [[params.repos]] name = "browserproxy" role = "Remote-browser service"