fix: upload the verification log right after the install writes it

Saving in the post step left the whole job between the install and the upload.
Anything running in that window — the job's tests, its build, a dependency's
own install scripts — can rewrite the log on disk, and the job's own cache
write would then publish a record claiming some other lockfile passed
verification, for every later job to restore and trust. No cache credentials
needed: the attacker rides the write the job performs anyway.

The log is complete the moment the install finishes, so it is uploaded there.
The post step still covers a job that installs in a step of its own, where
that is the first point the log is known to be final; the save is idempotent
across the two, and the process-local flags exist because main and post do not
share state within a run.
This commit is contained in:
Zoltan Kochan
2026-08-13 17:03:37 +02:00
parent b543421fa5
commit e6cb65ab2f
4 changed files with 156 additions and 128 deletions
+4 -1
View File
@@ -29,11 +29,14 @@ async function runMain() {
await restoreCache(inputs)
pnpmInstall(inputs)
await saveVerificationCache()
}
async function runPost() {
const inputs = JSON.parse(getState('inputs')) as Inputs
// pnpm versions before pnpm/pnpm#13893 delete the log during a store prune.
// Covers a job that installs in a later step of its own; when this action
// installed, the log was already saved then. Runs before the prune because
// pnpm versions before pnpm/pnpm#13893 delete the log during one.
await saveVerificationCache()
pruneStore(inputs)
await saveCache(inputs)