fix(audit): preserve emoji in npm registry errors (#108208)

* fix(audit): keep registry errors valid Unicode

* style(audit): format registry error boundary test

* docs(audit): document direct Node import floor

Co-authored-by: Leon-SK668 <0668001470@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
This commit is contained in:
Leon-SK668
2026-07-16 17:53:09 -07:00
committed by GitHub
co-authored by Peter Steinberger
parent c6ebd6be34
commit 3da3318c56
2 changed files with 23 additions and 1 deletions
+3 -1
View File
@@ -5,6 +5,8 @@ import { readFile } from "node:fs/promises";
import path from "node:path";
import process from "node:process";
import { pathToFileURL } from "node:url";
// This zero-install hook runs on Node 22.22.3+, where native TypeScript stripping is enabled.
import { truncateUtf16Safe } from "../../packages/normalization-core/src/utf16-slice.ts";
import { readBoundedResponseText as readBoundedResponseTextWithLimit } from "../lib/bounded-response.mjs";
const DEFAULT_REGISTRY = "https://registry.npmjs.org";
@@ -783,7 +785,7 @@ export async function readBoundedBulkAdvisoryErrorText(
text += decoder.decode(value, { stream: true });
if (text.length > maxChars) {
text = text.slice(0, maxChars);
text = truncateUtf16Safe(text, maxChars);
truncated = true;
break;
}
+20
View File
@@ -248,6 +248,26 @@ snapshots:
expect(text.length).toBeLessThan(4200);
});
it.each([
{
caseName: "drops a split surrogate pair",
responseBody: `abc\u{1f600}tail`,
expectedText: "abc\n[truncated]",
},
{
caseName: "preserves a complete surrogate pair",
responseBody: `ab\u{1f600}tail`,
expectedText: `ab\u{1f600}\n[truncated]`,
},
])(
"keeps bulk advisory error truncation UTF-16 safe: $caseName",
async ({ responseBody, expectedText }) => {
const response = new Response(responseBody, { status: 500 });
await expect(readBoundedBulkAdvisoryErrorText(response, 4)).resolves.toBe(expectedText);
},
);
it("aborts stalled bulk advisory requests", async () => {
let signal: AbortSignal | undefined;
const request = fetchBulkAdvisories({