Skip to content

ci: gate npm publication on browser-compatible imports - #2500

Merged
jbeckwith-oai merged 1 commit into
mainfrom
codex/guard-browser-release-imports
Aug 27, 2026
Merged

ci: gate npm publication on browser-compatible imports#2500
jbeckwith-oai merged 1 commit into
mainfrom
codex/guard-browser-release-imports

Conversation

@jbeckwith-oai

Copy link
Copy Markdown
Contributor

Summary

  • add a release-only, read-only browser-compatibility job between immutable release validation and protected npm publication
  • build and npm pack the exact verified release commit, then link the packed native-browser ESM graph and reject browser-unresolvable package specifiers or imports outside the artifact
  • preserve SHA-pinned actions, frozen dependency installation, protected release/publish environments, immutable commit binding, and OIDC-only npm publishing

Dependency and rollout

Verification

  • pnpm build
  • pnpm lint
  • pnpm exec tsc --noEmit
  • node --experimental-strip-types scripts/check-node-version-policy.ts
  • executed the exact workflow scripts against the current packed artifact (expected failure on #x509-transport-state) and a temporary repaired artifact (173 modules linked)
  • checked valid relative imports, rejected bare/private specifiers and package-root escapes, and asserted workflow ordering, immutable SHA binding, action pinning, least privilege, protected environments, and OIDC isolation
  • two consecutive clean adversarial-review rounds with two independent fresh-context, read-only reviewers per round

@jbeckwith-oai
jbeckwith-oai requested a review from a team as a code owner August 27, 2026 05:55
@openai-sdks

openai-sdks Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

OkTest Summary

237/237 SDK tests passed in 11.55s for Node SDK PR #2500.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 314ms
tests/chat-completions-create.test.ts ✅ Passed 273ms
tests/chat-completions-stream.test.ts ✅ Passed 243ms
tests/files-content-binary.test.ts ✅ Passed 247ms
tests/files-create-multipart.test.ts ✅ Passed 208ms
tests/files-list-pagination.test.ts ✅ Passed 227ms
tests/initialize-config.test.ts ✅ Passed 216ms
tests/instance-isolation.test.ts ✅ Passed 189ms
tests/models-list.test.ts ✅ Passed 187ms
tests/responses-background-lifecycle.test.ts ✅ Passed 280ms
tests/responses-body-method-errors.test.ts ✅ Passed 296ms
tests/responses-cancel-timeout.test.ts ✅ Passed 199ms
tests/responses-cancel.test.ts ✅ Passed 231ms
tests/responses-compact-retries.test.ts ✅ Passed 330ms
tests/responses-compact.test.ts ✅ Passed 353ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 148ms
tests/responses-create-advanced.test.ts ✅ Passed 271ms
tests/responses-create-disconnect.test.ts ✅ Passed 1.132s
tests/responses-create-errors.test.ts ✅ Passed 213ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 245ms
tests/responses-create-retries.test.ts ✅ Passed 391ms
tests/responses-create-stream-failures.test.ts ✅ Passed 303ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 2.174s
tests/responses-create-stream-wire.test.ts ✅ Passed 2.626s
tests/responses-create-stream.test.ts ✅ Passed 87ms
tests/responses-create-terminal-states.test.ts ✅ Passed 230ms
tests/responses-create-timeout.test.ts ✅ Passed 207ms
tests/responses-create.test.ts ✅ Passed 282ms
tests/responses-delete.test.ts ✅ Passed 242ms
tests/responses-input-items-errors.test.ts ✅ Passed 242ms
tests/responses-input-items-list.test.ts ✅ Passed 208ms
tests/responses-input-items-options.test.ts ✅ Passed 286ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 227ms
tests/responses-input-tokens-count.test.ts ✅ Passed 302ms
tests/responses-malformed-inputs.test.ts ✅ Passed 2.337s
tests/responses-not-found-errors.test.ts ✅ Passed 234ms
tests/responses-parse.test.ts ✅ Passed 214ms
tests/responses-retrieve-retries.test.ts ✅ Passed 345ms
tests/responses-retrieve.test.ts ✅ Passed 231ms
tests/responses-stored-method-errors.test.ts ✅ Passed 651ms
tests/retry-behavior.test.ts ✅ Passed 3.126s
tests/sdk-error-shape.test.ts ✅ Passed 299ms

View OkTest run #33044048725

SDK merge (c8d6d5662e43) · head (1c943049b797) · base (76b73a9c73aa) · OkTest (2b1bdfd25e98)

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 27, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-27T05:56:52.941541Z 1c94304 PR opened
🔒 Security Review Completed 2026-08-27T05:57:03.365108Z 1c94304 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

32 mixed files remain; 0 existing customizations changed.

Compared 76b73a9c73aa1c943049b797. Generated baselines verified.

32 existing customizations unchanged
  • api.md
  • scripts/castiron/README.md
  • scripts/castiron/custom_code_report.py
  • scripts/castiron/test_custom_code_report.py
  • src/client.ts
  • src/resources/audio/transcriptions.ts
  • src/resources/audio/translations.ts
  • src/resources/beta/assistants.ts
  • src/resources/beta/beta.ts
  • src/resources/beta/index.ts
  • src/resources/beta/responses/internal-base.ts
  • src/resources/beta/responses/responses.ts
  • src/resources/beta/threads/index.ts
  • src/resources/beta/threads/runs/index.ts
  • src/resources/beta/threads/runs/runs.ts
  • src/resources/beta/threads/threads.ts
  • src/resources/chat/completions/completions.ts
  • src/resources/chat/completions/index.ts
  • src/resources/conversations/index.ts
  • src/resources/embeddings.ts
  • src/resources/files.ts
  • src/resources/fine-tuning/checkpoints/permissions.ts
  • src/resources/images.ts
  • src/resources/responses/internal-base.ts
  • src/resources/responses/responses.ts
  • src/resources/skills/skills.ts
  • src/resources/skills/versions/versions.ts
  • src/resources/vector-stores/file-batches.ts
  • src/resources/vector-stores/files.ts
  • src/resources/webhooks/index.ts
  • src/resources/webhooks/webhooks.ts
  • tests/lib/data-residency.test.ts

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 33044068289 --repo openai/openai-node \
  --name castiron-custom-code-33044068289-1 --dir /tmp/castiron-custom-code-33044068289-1
git apply --stat /tmp/castiron-custom-code-33044068289-1/custom-code.patch
cat /tmp/castiron-custom-code-33044068289-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 76b73a9c73aafe11c60a425a82898705f1db966d 1c943049b797345c181fa8a227653436b9a2f06c
python3 scripts/castiron/custom_code_report.py report \
  --base 76b73a9c73aafe11c60a425a82898705f1db966d \
  --head 1c943049b797345c181fa8a227653436b9a2f06c --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-1c943049b797
cat /tmp/castiron-custom-code-1c943049b797/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@HAYDEN-OAI HAYDEN-OAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed immutable protected-main release SHA validation across the compatibility and publication jobs, packed native-ESM graph resolution and package-root containment, fail-closed job ordering, pinned actions, read-only gate permissions, and exclusive OIDC access in the protected publish environment. Publication remains blocked until the verified release artifact passes browser import validation.

@jbeckwith-oai
jbeckwith-oai added this pull request to the merge queue Aug 27, 2026
Merged via the queue into main with commit 08f201c Aug 27, 2026
36 checks passed
@jbeckwith-oai
jbeckwith-oai deleted the codex/guard-browser-release-imports branch August 27, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants