Skip to content

fix: skip allow-scripts hook under update-lockfile mode - #1140

Merged
rekmarks-consensys-1 merged 1 commit into
mainfrom
rekmarks/allow-scripts-update-lockfile
Oct 2, 2026
Merged

rekmarks-consensys-1 merged 1 commit into
mainfrom
rekmarks/allow-scripts-update-lockfile

Conversation

@rekmarks-consensys-1

@rekmarks-consensys-1 rekmarks-consensys-1 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Explanation

Renovate regenerates yarn.lock by running yarn install --mode=update-lockfile, which skips the link step. The vendored LavaMoat allow-scripts plugin's afterAllInstalled hook then runs yarn run allow-scripts. With nothing linked, yarn run can't find the binary, the hook calls process.exit(1), and Renovate reports an artifact failure (#1132). Renovate then opens dependency PRs whose yarn.lock doesn't match the updated ranges, as in #1128.

This patches the hook to return early when the install mode is update-lockfile.

Why skipping the hook in this mode is safe

  • No build scripts run in this mode. Project.install returns from the link step before linkEverything, and that function contains the build step where preinstall/install/postinstall run.
  • Some code can still run during the fetch step, but the hook never covered it. Yarn's fetchers for git: dependencies and GitHub tarballs pack the project in a subprocess, which runs its own prepare/prepack/install scripts. The exec: protocol also runs code at fetch time. All of this happens before afterAllInstalled, in every install mode, so the hook couldn't stop it with or without this patch. This repo's lockfile has none of these: it resolves only npm:, workspace: and patch:.
  • The hook can't check anything in this mode. Without node_modules it fails, which is the bug. With node_modules present (a local run), the tree wasn't relinked, so allow-scripts would only re-check the old packages and might re-run their allowed scripts. None of the newly locked packages would be checked.
  • Later installs still run the check. The hook is stateless and fires at the end of every other install, including plain installs, skip-build, and yarn add/up/dedupe. On a Renovate PR, the changed yarn.lock misses the CI node_modules cache. CI then runs yarn --immutable and allow-scripts against the new tree, and fails if a new package has an unlisted install script.

Upstream (LavaMoat/LavaMoat, packages/yarn-plugin-allow-scripts/sources/index.ts) has the same unconditional hook. Re-importing the plugin from the spec URL in .yarnrc.yml would undo this patch until LavaMoat ships the same check.

Changes

  • .yarn/plugins/@yarnpkg/plugin-allow-scripts.cjs: skip the afterAllInstalled hook when options.mode === "update-lockfile". .gitattributes marks this file as binary; use git show --text to see the diff.

Testing

I tested on a clean git archive export with no node_modules, which matches what Renovate starts from. With the old plugin, yarn install --mode=update-lockfile fails with Renovate's error (Couldn't find the node_modules state file … (findPackageLocation)). With the patched plugin it completes and writes the lockfile. A normal yarn install produced the same allow-scripts output with both plugins. The claims about Yarn's behavior come from reading the Yarn 4.12.0 source: the hook's arguments, the install-mode values, where the link step returns early, and the external-project packing in the git fetcher.

🤖 Generated with Claude Code


Note

Low Risk
Single conditional in a vendored Yarn plugin; supply-chain checks still run on full installs, only lockfile-only Renovate runs skip the hook.

Overview
Fixes Renovate lockfile updates that fail when the vendored LavaMoat plugin-allow-scripts runs yarn run allow-scripts after yarn install --mode=update-lockfile. That mode skips linking, so the allow-scripts binary is missing and the hook exits with code 1.

The patch changes afterAllInstalled to no-op when install mode is update-lockfile, with a short comment explaining why. Normal installs (CI yarn --immutable, local yarn install, etc.) still run the hook unchanged.

Reviewed by Cursor Bugbot for commit c990f38. Bugbot is set up for automated code reviews on this repo. Configure here.

@rekmarks-consensys-1
rekmarks-consensys-1 requested a review from a team as a code owner October 1, 2026 19:31
@rekmarks-consensys-1 rekmarks-consensys-1 added the no-changelog Indicates that no changelog updates are required, and that related CI checks should be skipped. label Oct 1, 2026
@rekmarks-consensys-1
rekmarks-consensys-1 marked this pull request as draft October 1, 2026 19:39
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 73.33%
🟰 ±0%
9973 / 13599
🔵 Statements 73.12%
🟰 ±0%
10102 / 13814
🔵 Functions 73.75%
🟰 ±0%
2333 / 3163
🔵 Branches 67.69%
🟰 ±0%
4111 / 6073
File CoverageNo changed files found.
Generated in workflow #5107 for commit c990f38 by the Vitest Coverage Report Action

@rekmarks-consensys-1
rekmarks-consensys-1 marked this pull request as ready for review October 2, 2026 17:19
Renovate regenerates yarn.lock with `yarn install --mode=update-lockfile`, which skips the link step. The allow-scripts plugin's afterAllInstalled hook then runs `yarn run allow-scripts`, which can't find the binary and fails the install, so Renovate reports an artifact failure and opens PRs without lockfile updates.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rekmarks-consensys-1
rekmarks-consensys-1 force-pushed the rekmarks/allow-scripts-update-lockfile branch from 6875c70 to c990f38 Compare October 2, 2026 17:19

@ci-belphegor ci-belphegor left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a drawbridge, maybe a berm

@rekmarks-consensys-1
rekmarks-consensys-1 added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit 226fd91 Oct 2, 2026
28 checks passed
@rekmarks-consensys-1
rekmarks-consensys-1 deleted the rekmarks/allow-scripts-update-lockfile branch October 2, 2026 17:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Indicates that no changelog updates are required, and that related CI checks should be skipped.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants