litellm/tests/claude_code
Cursor Agent c941291567
fix(ci): scrub provider secrets from env around PR-gate resolver + npm install
Address two related Veria comments on the claude_code_compat_pr_gate
job:

1. (line ~2320) The PR-gate version resolver is PR-controlled Python
   that runs in the same CircleCI job as the provider secrets injected
   later into the proxy container. A malicious PR could modify
   tests/claude_code/pr_gate_version_resolver.py to read
   ANTHROPIC_API_KEY / AWS_* / VERTEXAI_* / AZURE_FOUNDRY_* /
   GITHUB_TOKEN out of os.environ and exfiltrate them over the
   resolver's outbound npm registry HTTPS call.

2. (line ~2335) `npm install -g @anthropic-ai/claude-code` runs the
   package's `postinstall: node install.cjs` script (verified
   against the npm registry metadata for @anthropic-ai/claude-code),
   which executes arbitrary code from npm with the full job env.
   `claude --version` on the next line also runs package code. A
   compromised package release (or transitive registry hijack) could
   exfiltrate the same provider credentials. --ignore-scripts is not
   viable: the postinstall is the step that fetches the platform
   binary, so skipping it would leave the install unusable.

Mitigation:

- Wrap both invocations in `env -i` with a minimal allowlist
  (PATH / HOME / USER / TERM / LANG / LC_ALL / TMPDIR — plus
  NVM_DIR + CLAUDE_CODE_VERSION on the npm step). BASH_ENV is
  intentionally NOT passed through so the scrubbed subshell can't
  re-source prior steps' exports.

- Pin the scrub with two new unit tests in
  test_circleci_pr_gate_wiring.py so a future YAML refactor cannot
  silently drop the env -i wrapper and revert the mitigation. The
  tests verify both that `env -i` is present in each step and that
  it precedes the actual at-risk invocation in the command body.

Verified locally that `env -i PATH=$PATH HOME=$HOME ... uv run
--no-sync python -m tests.claude_code.pr_gate_version_resolver` still
resolves and prints a CLI version successfully.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-05-18 00:00:35 +00:00
..
_builder_unit_tests fix(claude_code): harden parallel runner + de-dup basic_messaging cells 2026-05-17 06:35:15 +00:00
_driver_unit_tests fix(claude_code): verify streaming wire in basic_messaging_streaming cells 2026-05-17 22:47:47 +00:00
_pr_gate_unit_tests fix(ci): scrub provider secrets from env around PR-gate resolver + npm install 2026-05-18 00:00:35 +00:00
_publisher_unit_tests fix(cron): bugbot — paginate all release pages to pick highest-semver stable 2026-05-17 21:39:36 +00:00
basic_messaging_non_streaming fix(claude_code): harden parallel runner + de-dup basic_messaging cells 2026-05-17 06:35:15 +00:00
basic_messaging_streaming fix(claude_code): verify streaming wire in basic_messaging_streaming cells 2026-05-17 22:47:47 +00:00
count_tokens feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
cron_vm fix(cron): bugbot — paginate all release pages to pick highest-semver stable 2026-05-17 21:39:36 +00:00
long_context_1m feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
pdf_input compat-matrix: parallel-fanout refactor + 5 new feature dirs + rate limiter 2026-05-06 23:31:19 +00:00
prompt_caching_1h compat-matrix: parallel-fanout refactor + 5 new feature dirs + rate limiter 2026-05-06 23:31:19 +00:00
prompt_caching_5m compat-matrix: parallel-fanout refactor + 5 new feature dirs + rate limiter 2026-05-06 23:31:19 +00:00
structured_outputs feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
thinking feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
thinking_with_tool_use compat-matrix: fix vision, extended_thinking, web_search test bugs 2026-05-07 02:16:10 +00:00
tool_search feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
tool_use compat-matrix: parallel-fanout refactor + 5 new feature dirs + rate limiter 2026-05-06 23:31:19 +00:00
tool_use_streaming compat-matrix: parallel-fanout refactor + 5 new feature dirs + rate limiter 2026-05-06 23:31:19 +00:00
vision compat-matrix: fix vision, extended_thinking, web_search test bugs 2026-05-07 02:16:10 +00:00
web_search compat-matrix: fix vision, extended_thinking, web_search test bugs 2026-05-07 02:16:10 +00:00
__init__.py RALPH: tracer-bullet for Claude Code compatibility matrix (#26477, PRD #26476) 2026-05-06 23:27:05 +00:00
_basic_messaging.py fix(claude_code): verify streaming wire in basic_messaging_streaming cells 2026-05-17 22:47:47 +00:00
cli_driver.py fix(claude_code): harden parallel runner + de-dup basic_messaging cells 2026-05-17 06:35:15 +00:00
conftest.py fix: clear manifest cache between sessions and align PR gate pytest with cron 2026-05-17 07:04:49 +00:00
http_probe.py fix(claude_code): rate-limit HTTP probe rows alongside CLI rows 2026-05-17 01:40:23 +00:00
manifest.yaml feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
matrix_builder.py RALPH: tracer-bullet for Claude Code compatibility matrix (#26477, PRD #26476) 2026-05-06 23:27:05 +00:00
pr_gate_version_resolver.py RALPH: compat matrix slice 3 - wire PR gate in CircleCI (#26479, PRD #26476) 2026-05-06 23:27:05 +00:00
rate_limiter.py compat-matrix: parallel-fanout refactor + 5 new feature dirs + rate limiter 2026-05-06 23:31:19 +00:00
run_compat.sh feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
sample_compatibility-matrix.json feat(claude_code): rename thinking row + add 4 feature rows (15 total) 2026-05-16 20:37:01 +00:00
test_config.yaml compat-matrix: parallel-fanout refactor + 5 new feature dirs + rate limiter 2026-05-06 23:31:19 +00:00