Repository navigation
fix: skip allow-scripts hook under update-lockfile mode - #1140
Merged
Merged
Conversation
rekmarks-consensys-1
marked this pull request as draft
October 1, 2026 19:39
Contributor
Coverage Report
File CoverageNo changed files found. |
rekmarks-consensys-1
marked this pull request as ready for review
October 2, 2026 17:19
Renovate regenerates yarn.lock with `yarn install --mode=update-lockfile`, which skips the link step. The allow-scripts plugin's afterAllInstalled hook then runs `yarn run allow-scripts`, which can't find the binary and fails the install, so Renovate reports an artifact failure and opens PRs without lockfile updates. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rekmarks-consensys-1
force-pushed
the
rekmarks/allow-scripts-update-lockfile
branch
from
October 2, 2026 17:19
6875c70 to
c990f38
Compare
rekmarks-consensys-1
enabled auto-merge
October 2, 2026 17:32
ci-belphegor
approved these changes
Oct 2, 2026
ci-belphegor
left a comment
Contributor
There was a problem hiding this comment.
Not a drawbridge, maybe a berm
rekmarks-consensys-1
deleted the
rekmarks/allow-scripts-update-lockfile
branch
October 2, 2026 17:43
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explanation
Renovate regenerates
yarn.lockby runningyarn install --mode=update-lockfile, which skips the link step. The vendored LavaMoat allow-scripts plugin'safterAllInstalledhook then runsyarn run allow-scripts. With nothing linked,yarn runcan't find the binary, the hook callsprocess.exit(1), and Renovate reports an artifact failure (#1132). Renovate then opens dependency PRs whoseyarn.lockdoesn't match the updated ranges, as in #1128.This patches the hook to return early when the install mode is
update-lockfile.Why skipping the hook in this mode is safe
Project.installreturns from the link step beforelinkEverything, and that function contains the build step wherepreinstall/install/postinstallrun.git:dependencies and GitHub tarballs pack the project in a subprocess, which runs its ownprepare/prepack/install scripts. Theexec:protocol also runs code at fetch time. All of this happens beforeafterAllInstalled, in every install mode, so the hook couldn't stop it with or without this patch. This repo's lockfile has none of these: it resolves onlynpm:,workspace:andpatch:.node_modulesit fails, which is the bug. Withnode_modulespresent (a local run), the tree wasn't relinked, soallow-scriptswould only re-check the old packages and might re-run their allowed scripts. None of the newly locked packages would be checked.skip-build, andyarn add/up/dedupe. On a Renovate PR, the changedyarn.lockmisses the CInode_modulescache. CI then runsyarn --immutableand allow-scripts against the new tree, and fails if a new package has an unlisted install script.Upstream (
LavaMoat/LavaMoat,packages/yarn-plugin-allow-scripts/sources/index.ts) has the same unconditional hook. Re-importing the plugin from thespecURL in.yarnrc.ymlwould undo this patch until LavaMoat ships the same check.Changes
.yarn/plugins/@yarnpkg/plugin-allow-scripts.cjs: skip theafterAllInstalledhook whenoptions.mode === "update-lockfile"..gitattributesmarks this file as binary; usegit show --textto see the diff.Testing
I tested on a clean
git archiveexport with nonode_modules, which matches what Renovate starts from. With the old plugin,yarn install --mode=update-lockfilefails with Renovate's error (Couldn't find the node_modules state file … (findPackageLocation)). With the patched plugin it completes and writes the lockfile. A normalyarn installproduced the same allow-scripts output with both plugins. The claims about Yarn's behavior come from reading the Yarn 4.12.0 source: the hook's arguments, the install-mode values, where the link step returns early, and the external-project packing in the git fetcher.🤖 Generated with Claude Code
Note
Low Risk
Single conditional in a vendored Yarn plugin; supply-chain checks still run on full installs, only lockfile-only Renovate runs skip the hook.
Overview
Fixes Renovate lockfile updates that fail when the vendored LavaMoat
plugin-allow-scriptsrunsyarn run allow-scriptsafteryarn install --mode=update-lockfile. That mode skips linking, so the allow-scripts binary is missing and the hook exits with code 1.The patch changes
afterAllInstalledto no-op when install mode isupdate-lockfile, with a short comment explaining why. Normal installs (CIyarn --immutable, localyarn install, etc.) still run the hook unchanged.Reviewed by Cursor Bugbot for commit c990f38. Bugbot is set up for automated code reviews on this repo. Configure here.