Skip to content

Guard the Google provider URL and stop silent CLI fallbacks - #1

Merged
MaciejZet merged 2 commits into
mainfrom
fix/oss-street-2026-09-30
Sep 30, 2026
Merged

MaciejZet merged 2 commits into
mainfrom
fix/oss-street-2026-09-30

Conversation

@MaciejZet

Copy link
Copy Markdown
Collaborator

Summary

  • The Google provider URL is checked with the existing URL and DNS guards before any fetch.
  • Unknown market, device, or depth values now fail instead of silently falling back. Depth stays limited to 10 or 20.
  • The CLI refuses to start on Node older than 22. npm audit highs are pinned with overrides, and CI runs Prettier.
  • Docs describe a clone plus npm ci. This package is not published to npm.

The Prettier pass is in the same commit as the guard, so the diff is larger than the behavior change. The behavior sits in serp-providers.ts, cli.ts, bin/rankproof.mjs, and the docs.

Test plan

  • npm test
  • npm run test:scaffold
  • npm run typecheck
  • npm run lint (two existing react-refresh warnings, no errors)
  • npm run format:check
  • npm audit shows no high advisories
  • Playwright e2e was not run in this pass

Unknown market, device and depth values now error, scan uses --depth, Node older than 22 stops at startup, and the install docs no longer point at an unpublished npm package.
@MaciejZet
MaciejZet merged commit f9d38db into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant