Skip to content

Add opt-in portable unsigned extension packaging - #29

Open
RVZO6 wants to merge 4 commits into
SunkenInTime:mainfrom
RVZO6:fix/portable-extension-packaging
Open

RVZO6 wants to merge 4 commits into
SunkenInTime:mainfrom
RVZO6:fix/portable-extension-packaging

Conversation

@RVZO6

@RVZO6 RVZO6 commented Oct 9, 2026 •

Copy link
Copy Markdown

Problem

The existing packaging command requires PowerShell, so contributors cannot build a review artifact with the repository's Node toolchain alone on macOS or Linux.

Change

Add an opt-in pnpm package:portable command using only Node and Git. It emits deterministic ZIP/XPI extension artifacts, a committed review-source archive, and SHA-256 checksums under dist. Use the project's existing release version, require clean committed source, reject symlinks and unsupported ZIP64 sizes, and write forward-slash UTF-8 archive paths.

The existing PowerShell command, release workflow, and ZIP/source checksum filenames are preserved. There is no fork-specific metadata requirement, signing, publication, installation, or native companion change.

Validation

  • pnpm test passes on this branch.
  • Two consecutive builds on macOS produce identical artifact checksums.
  • Python's independent ZIP reader validates each entry's CRC and verifies every ZIP/XPI filename and byte against extension source.
  • Maintained coverage in tests/test-portable-packaging.mjs compares every extension byte against the review source and verifies ignored files and real CRLF checkouts cannot change any artifact. It runs in npm test and npm run test:package. Both pass on Linux ARM64; Windows execution has not been directly validated. Both artifacts use one canonical committed Git tree, including committed file modes.

Generated by GPT 6.1 Sol in Codex, using T3 Code.

RetriggerConfidence Score: 5/5

Safe to merge based on the reviewed changes. No outstanding blocking findings remain.

Summary

Adds opt-in pnpm package:portable packaging with Node and Git.

  • Contributors can build unsigned extension review archives with Node and Git.

No new issues were found. The earlier archive mismatch is also fixed: both archives use the same frozen HEAD tree.

Reviews (3) · Last reviewed commit: "Disable inherited signing for packaging ..." · Reviewed by Greptile

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 34 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 147e80be-ede3-48a8-98e2-48b1eb5bbd2d
📥 Commits

Reviewing files that changed from the base of the PR and between 634eddf and cc6d865.

📒 Files selected for processing (4)
  • README.md
  • package.json
  • scripts/package-extension.mjs
  • tests/test-portable-packaging.mjs
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread scripts/package-extension.mjs Outdated
@RVZO6

RVZO6 commented Oct 9, 2026

Copy link
Copy Markdown
Author

Review fixes pushed in 3bb875f.

The packaging-source finding is addressed and its thread has a reply/resolution. Full npm test, npm run test:package, and a clean committed npm run package:portable pass on Linux ARM64. Both archives use one committed Git snapshot. Maintained tests verify byte-for-byte extension/review-source agreement, ignored-file exclusion, and identical artifacts from a real CRLF checkout. An independent Python ZIP reader also validates CRCs, membership, and committed modes.

The updated changes are ready for another review; the latest review checks are still running.

Comment thread tests/test-portable-packaging.mjs Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant