pj 7f9c5df7db fix(ci): close shell injection into the npm publish job
A refname is attacker-controlled and git permits backtick, $, (, ; and |
in it. Three sites substituted it into a run: block, and NODE_AUTH_TOKEN
sat at job level, so a pushed tag ran arbitrary commands with the publish
credential in reach.

The tag now goes through env:, is validated against an anchored version
pattern before anything consumes it, and reaches the other jobs as a job
output. The token is scoped to the publish step. release-npm declares
contents: read instead of inheriting the repo default.
2026-08-16 01:00:40 +05:30
2026-08-15 15:55:19 +05:30
2026-06-09 20:13:54 +05:30

sanderling

Autonomous property-based testing for mobile and web apps.

You write rules that must always hold about your app. sanderling explores the app on its own for minutes or hours, performing thousands of taps, swipes, and inputs, and records every step where a rule breaks. No scripted test paths. One TypeScript spec runs against Android, iOS, and web builds of the same app.

import { extract, always } from "@sanderling/spec";
import { defaultActions } from "@sanderling/spec/defaults";
import { noUncaughtExceptions } from "@sanderling/spec/defaults/properties";

const balance = extract("balance", s =>
  parseInt(s.ax.find({ testTag: "Balance" })?.text ?? "0", 10));

export const properties = {
  noUncaughtExceptions,
  balanceNeverNegative: always(() => balance.current >= 0),
};

export const actionsRoot = defaultActions;

Every run produces a trace: one JSON line and one screenshot per step. sanderling replay opens it in a web UI for stepping through actions, screenshots, property timelines, and violations.

Alpha. Android, iOS, and web (Chrome driver only). Full scope in the v0.1.0 roadmap.

Docs


sanderling

sanderling, a wading bird that probes the shoreline for bugs that lie beneath.

S
Description
No description provided
Readme Apache-2.0
51 MiB
0 Stars 1 Watchers 0 Forks
Languages
Go 74.6%
TypeScript 15.2%
Kotlin 5.5%
Shell 2.7%
Swift 1%
Other 0.9%