Skip to content

Fix npm artifact false alarms and stale builtins manifest references - #730

Merged
tamashi095 merged 7 commits into
mainfrom
codex/interchange-npm-prune
Sep 11, 2026
Merged

Fix npm artifact false alarms and stale builtins manifest references#730
tamashi095 merged 7 commits into
mainfrom
codex/interchange-npm-prune

Conversation

@tamashi095

@tamashi095 tamashi095 commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

The interchange artifact scan now ignores actual node_modules directories at any depth, so installed dependencies containing Wasm do not produce false failures. Source artifacts remain rejected, and the existing root target exclusion and traversal-error handling are preserved.

Builtins benchmark manifest references now match the current fixture manifest across the four stale consumers. A cheap required-CI check detects drift in all seven declarations, including synthetic test rows and the already-current bench consumer. Fixture bytes and PCM/meter identities are unchanged.

Validation: independent Astra XHIGH review of both Astra LOW implementations; complete existing policy and hermetic lifecycle controls; actual stale-consumer and old-scan rejection controls; focused audit tests/Clippy and CI-routing checks. Reviewed sources: #285 3625c5d2 and #176 cc11fea3, combined at f83e80d7, with the dependent audit report checksum corrected at 9f3ef5aa. No timed benchmark or shipped artifact pin change. This does not qualify the historical benchmark runner as runnable.

Delivers #285 and #176 after required PR and exact-main qualification.

The initial PR run 34566763819 exposed the dependent audit-report checksum. The correction derives its new hash from the exact report: changing only accepted_manifest_sha256 back reproduces the old pin. Trace, lifecycle, zero-violation and exact-hash gates remain intact.

@tamashi095
tamashi095 merged commit af7c728 into main Sep 11, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant