|
| 1 | +import type { PackageVersionInfo } from '#shared/types' |
| 2 | +import { compare } from 'semver' |
| 3 | + |
| 4 | +export interface PublishSecurityDowngrade { |
| 5 | + downgradedVersion: string |
| 6 | + downgradedPublishedAt?: string |
| 7 | + trustedVersion: string |
| 8 | + trustedPublishedAt?: string |
| 9 | +} |
| 10 | + |
| 11 | +type VersionWithIndex = PackageVersionInfo & { |
| 12 | + index: number |
| 13 | + timestamp: number |
| 14 | +} |
| 15 | + |
| 16 | +function toTimestamp(time?: string): number { |
| 17 | + if (!time) return Number.NaN |
| 18 | + return Date.parse(time) |
| 19 | +} |
| 20 | + |
| 21 | +function sortByRecency(a: VersionWithIndex, b: VersionWithIndex): number { |
| 22 | + const aValid = Number.isFinite(a.timestamp) |
| 23 | + const bValid = Number.isFinite(b.timestamp) |
| 24 | + |
| 25 | + if (aValid && bValid && a.timestamp !== b.timestamp) { |
| 26 | + return b.timestamp - a.timestamp |
| 27 | + } |
| 28 | + |
| 29 | + if (aValid !== bValid) { |
| 30 | + return aValid ? -1 : 1 |
| 31 | + } |
| 32 | + |
| 33 | + const semverOrder = compare(b.version, a.version) |
| 34 | + if (semverOrder !== 0) return semverOrder |
| 35 | + |
| 36 | + return a.index - b.index |
| 37 | +} |
| 38 | + |
| 39 | +/** |
| 40 | + * Detects a security downgrade where the newest publish is not trusted, |
| 41 | + * but an older publish was trusted (e.g. OIDC/provenance -> manual publish). |
| 42 | + */ |
| 43 | +export function detectPublishSecurityDowngrade( |
| 44 | + versions: PackageVersionInfo[], |
| 45 | +): PublishSecurityDowngrade | null { |
| 46 | + if (versions.length < 2) return null |
| 47 | + |
| 48 | + const sorted = versions |
| 49 | + .map((version, index) => ({ |
| 50 | + ...version, |
| 51 | + index, |
| 52 | + timestamp: toTimestamp(version.time), |
| 53 | + })) |
| 54 | + .sort(sortByRecency) |
| 55 | + |
| 56 | + const latest = sorted[0] |
| 57 | + if (!latest || latest.hasProvenance) return null |
| 58 | + |
| 59 | + const latestTrusted = sorted.find(version => version.hasProvenance) |
| 60 | + if (!latestTrusted) return null |
| 61 | + |
| 62 | + return { |
| 63 | + downgradedVersion: latest.version, |
| 64 | + downgradedPublishedAt: latest.time, |
| 65 | + trustedVersion: latestTrusted.version, |
| 66 | + trustedPublishedAt: latestTrusted.time, |
| 67 | + } |
| 68 | +} |
| 69 | + |
| 70 | +/** |
| 71 | + * Detects a security downgrade for a specific viewed version. |
| 72 | + * A version is considered downgraded when it has no provenance and |
| 73 | + * there exists an older trusted release. |
| 74 | + */ |
| 75 | +export function detectPublishSecurityDowngradeForVersion( |
| 76 | + versions: PackageVersionInfo[], |
| 77 | + viewedVersion: string, |
| 78 | +): PublishSecurityDowngrade | null { |
| 79 | + if (versions.length < 2 || !viewedVersion) return null |
| 80 | + |
| 81 | + const sorted = versions |
| 82 | + .map((version, index) => ({ |
| 83 | + ...version, |
| 84 | + index, |
| 85 | + timestamp: toTimestamp(version.time), |
| 86 | + })) |
| 87 | + .sort(sortByRecency) |
| 88 | + |
| 89 | + const currentIndex = sorted.findIndex(version => version.version === viewedVersion) |
| 90 | + if (currentIndex === -1) return null |
| 91 | + |
| 92 | + const current = sorted[currentIndex] |
| 93 | + if (!current || current.hasProvenance) return null |
| 94 | + |
| 95 | + const trustedOlder = sorted.slice(currentIndex + 1).find(version => version.hasProvenance) |
| 96 | + if (!trustedOlder) return null |
| 97 | + |
| 98 | + return { |
| 99 | + downgradedVersion: current.version, |
| 100 | + downgradedPublishedAt: current.time, |
| 101 | + trustedVersion: trustedOlder.version, |
| 102 | + trustedPublishedAt: trustedOlder.time, |
| 103 | + } |
| 104 | +} |
0 commit comments