Skip to content

fix(sign): Excluded the artifacts directory from the signed package - #3834

Open
MaxFreedomPollard wants to merge 3 commits into
mozilla:masterfrom
MaxFreedomPollard:fix/sign-artifacts
Open

MaxFreedomPollard wants to merge 3 commits into
mozilla:masterfrom
MaxFreedomPollard:fix/sign-artifacts

Conversation

@MaxFreedomPollard

@MaxFreedomPollard MaxFreedomPollard commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #1640.

web-ext build leaves the artifacts directory out of its package, but web-ext sign can include it. Files such as .crx packages, unpacked extension copies, and screenshots under web-ext-artifacts/ can then end up in the archive uploaded to AMO. Existing .zip and .xpi files are already excluded by the base ignore patterns.

sign() builds into a temporary directory, so build() previously made its file filter from that temporary output path instead of the real artifacts directory inside the source tree.

build() now accepts artifactsDirToIgnore for its own file filter, defaulting to its output artifactsDir. sign() passes the real artifacts directory through this option while keeping the temporary build output. Build constructs the filter in both commands. The existing --ignore-files handling and the behavior when the artifacts directory is outside the source tree remain unchanged.

A sign integration test checks that the archive contains manifest.json but excludes a prior .crx in the artifacts directory. A sign unit test checks that it passes the real directory to build. A build unit test checks that the directory used for filtering can differ from the output directory.

Validation: all 45 tests in test.build.js and test.sign.js passed. ESLint and Prettier passed for the four changed files.

The sign command builds its package into a temporary directory, and build
creates its default file filter from that temporary path. FileFilter only
adds ignore rules for the artifacts directory when it sits inside the
source directory, so a temporary path meant the rule was never added and
everything under web-ext-artifacts that is not a .zip or .xpi ended up in
the archive sent to AMO. Sign now builds the file filter itself from the
real artifacts directory and passes it to build. The same ignoreFiles are
still passed in, so --ignore-files is unaffected, and the existing
isSubPath guard keeps behaviour unchanged when --artifacts-dir points
outside the source directory.

@Rob--W Rob--W left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This patch seems to fix the issue at the wrong layer. The build command should exclude the artifacts directory; sign should not exclude files that the build includes, because otherwise someone testing the output of build may get a result that differs from what users would encounter after signing the package.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sign command should ignore web-ext-artifacts folder

2 participants