style(16): apply prettier formatting to satisfy CI format:check
CI / changes (pull_request) Successful in 2s
CI / fast-checks (pull_request) Successful in 1m23s
CI / api (pull_request) Successful in 1m0s
CI / harness (pull_request) Successful in 3m54s
CI / security (pull_request) Successful in 40s
CI / gate (pull_request) Successful in 1s
CI / changes (pull_request) Successful in 2s
CI / fast-checks (pull_request) Successful in 1m23s
CI / api (pull_request) Successful in 1m0s
CI / harness (pull_request) Successful in 3m54s
CI / security (pull_request) Successful in 40s
CI / gate (pull_request) Successful in 1s
This commit is contained in:
@@ -352,7 +352,7 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0 # Required: base.sha must be locally available for git log range (Pitfall 3)
|
fetch-depth: 0 # Required: base.sha must be locally available for git log range (Pitfall 3)
|
||||||
|
|
||||||
# ── Probe PR base/head SHA with merge-base fallback (A2 / OQ-1) ──────────
|
# ── Probe PR base/head SHA with merge-base fallback (A2 / OQ-1) ──────────
|
||||||
# github.event.pull_request.base.sha may be empty on some Gitea versions.
|
# github.event.pull_request.base.sha may be empty on some Gitea versions.
|
||||||
|
|||||||
@@ -28,11 +28,9 @@ describe('assertNotDevBypassInProduction', () => {
|
|||||||
process.env.NODE_ENV = 'production';
|
process.env.NODE_ENV = 'production';
|
||||||
process.env.DEV_AUTH_BYPASS = 'true';
|
process.env.DEV_AUTH_BYPASS = 'true';
|
||||||
|
|
||||||
const exitSpy = vi
|
const exitSpy = vi.spyOn(process, 'exit').mockImplementation((() => {
|
||||||
.spyOn(process, 'exit')
|
throw new Error('process.exit called');
|
||||||
.mockImplementation((() => {
|
}) as never);
|
||||||
throw new Error('process.exit called');
|
|
||||||
}) as never);
|
|
||||||
|
|
||||||
expect(() => assertNotDevBypassInProduction()).toThrow('process.exit called');
|
expect(() => assertNotDevBypassInProduction()).toThrow('process.exit called');
|
||||||
expect(exitSpy).toHaveBeenCalledWith(1);
|
expect(exitSpy).toHaveBeenCalledWith(1);
|
||||||
@@ -44,11 +42,9 @@ describe('assertNotDevBypassInProduction', () => {
|
|||||||
process.env.NODE_ENV = 'development';
|
process.env.NODE_ENV = 'development';
|
||||||
process.env.DEV_AUTH_BYPASS = 'true';
|
process.env.DEV_AUTH_BYPASS = 'true';
|
||||||
|
|
||||||
const exitSpy = vi
|
const exitSpy = vi.spyOn(process, 'exit').mockImplementation((() => {
|
||||||
.spyOn(process, 'exit')
|
throw new Error('process.exit called');
|
||||||
.mockImplementation((() => {
|
}) as never);
|
||||||
throw new Error('process.exit called');
|
|
||||||
}) as never);
|
|
||||||
|
|
||||||
expect(() => assertNotDevBypassInProduction()).not.toThrow();
|
expect(() => assertNotDevBypassInProduction()).not.toThrow();
|
||||||
expect(exitSpy).not.toHaveBeenCalled();
|
expect(exitSpy).not.toHaveBeenCalled();
|
||||||
@@ -60,11 +56,9 @@ describe('assertNotDevBypassInProduction', () => {
|
|||||||
process.env.NODE_ENV = 'production';
|
process.env.NODE_ENV = 'production';
|
||||||
delete process.env.DEV_AUTH_BYPASS;
|
delete process.env.DEV_AUTH_BYPASS;
|
||||||
|
|
||||||
const exitSpy = vi
|
const exitSpy = vi.spyOn(process, 'exit').mockImplementation((() => {
|
||||||
.spyOn(process, 'exit')
|
throw new Error('process.exit called');
|
||||||
.mockImplementation((() => {
|
}) as never);
|
||||||
throw new Error('process.exit called');
|
|
||||||
}) as never);
|
|
||||||
|
|
||||||
expect(() => assertNotDevBypassInProduction()).not.toThrow();
|
expect(() => assertNotDevBypassInProduction()).not.toThrow();
|
||||||
expect(exitSpy).not.toHaveBeenCalled();
|
expect(exitSpy).not.toHaveBeenCalled();
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ import { selectBlocking, partitionAdvisories, isWaived } from '../check-audit.mj
|
|||||||
|
|
||||||
// Fixture: a High advisory not in the allowlist
|
// Fixture: a High advisory not in the allowlist
|
||||||
const highUnwaived = {
|
const highUnwaived = {
|
||||||
'1': {
|
1: {
|
||||||
severity: 'high',
|
severity: 'high',
|
||||||
github_advisory_id: 'GHSA-test-unwaived-high',
|
github_advisory_id: 'GHSA-test-unwaived-high',
|
||||||
module_name: 'some-package',
|
module_name: 'some-package',
|
||||||
@@ -24,7 +24,7 @@ const highUnwaived = {
|
|||||||
|
|
||||||
// Fixture: a High advisory that IS in the allowlist
|
// Fixture: a High advisory that IS in the allowlist
|
||||||
const highWaived = {
|
const highWaived = {
|
||||||
'2': {
|
2: {
|
||||||
severity: 'high',
|
severity: 'high',
|
||||||
github_advisory_id: 'GHSA-gv7w-rqvm-qjhr',
|
github_advisory_id: 'GHSA-gv7w-rqvm-qjhr',
|
||||||
module_name: 'esbuild',
|
module_name: 'esbuild',
|
||||||
@@ -34,13 +34,13 @@ const highWaived = {
|
|||||||
|
|
||||||
// Fixture: only moderate/low advisories
|
// Fixture: only moderate/low advisories
|
||||||
const moderateLow = {
|
const moderateLow = {
|
||||||
'3': {
|
3: {
|
||||||
severity: 'moderate',
|
severity: 'moderate',
|
||||||
github_advisory_id: 'GHSA-mod-erate-test',
|
github_advisory_id: 'GHSA-mod-erate-test',
|
||||||
module_name: 'another-package',
|
module_name: 'another-package',
|
||||||
title: 'Moderate vulnerability',
|
title: 'Moderate vulnerability',
|
||||||
},
|
},
|
||||||
'4': {
|
4: {
|
||||||
severity: 'low',
|
severity: 'low',
|
||||||
github_advisory_id: 'GHSA-low-test-only',
|
github_advisory_id: 'GHSA-low-test-only',
|
||||||
module_name: 'yet-another',
|
module_name: 'yet-another',
|
||||||
|
|||||||
@@ -62,7 +62,9 @@ try {
|
|||||||
pins = JSON.parse(readFileSync(pinsPath, 'utf8'));
|
pins = JSON.parse(readFileSync(pinsPath, 'utf8'));
|
||||||
} catch {
|
} catch {
|
||||||
// Gracefully degrade — no pins means everything is treated as unpinned
|
// Gracefully degrade — no pins means everything is treated as unpinned
|
||||||
console.warn('[check-outdated] Warning: could not read outdated-pins.json; treating all pins as unknown');
|
console.warn(
|
||||||
|
'[check-outdated] Warning: could not read outdated-pins.json; treating all pins as unknown',
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
// ── Run pnpm audit to collect vulnerable module names ───────────────────────
|
// ── Run pnpm audit to collect vulnerable module names ───────────────────────
|
||||||
@@ -78,7 +80,9 @@ try {
|
|||||||
}
|
}
|
||||||
} catch {
|
} catch {
|
||||||
// Audit parse failure is non-fatal for the outdated report
|
// Audit parse failure is non-fatal for the outdated report
|
||||||
console.warn('[check-outdated] Warning: could not parse pnpm audit output; OUTDATED-WITH-ADVISORY cross-check skipped');
|
console.warn(
|
||||||
|
'[check-outdated] Warning: could not parse pnpm audit output; OUTDATED-WITH-ADVISORY cross-check skipped',
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
// ── Run pnpm outdated ────────────────────────────────────────────────────────
|
// ── Run pnpm outdated ────────────────────────────────────────────────────────
|
||||||
@@ -123,13 +127,13 @@ for (const [pkgName, info] of Object.entries(outdatedData)) {
|
|||||||
// file header); the authoritative advisory gate is check-audit.mjs.
|
// file header); the authoritative advisory gate is check-audit.mjs.
|
||||||
if (hasAdvisory) {
|
if (hasAdvisory) {
|
||||||
tiers.auditAdvisory.push(entry);
|
tiers.auditAdvisory.push(entry);
|
||||||
// Priority 2: major behind + intentional pin
|
// Priority 2: major behind + intentional pin
|
||||||
} else if (isMajorBehind && pinReason) {
|
} else if (isMajorBehind && pinReason) {
|
||||||
tiers.majorBehindIntentional.push({ ...entry, reason: pinReason });
|
tiers.majorBehindIntentional.push({ ...entry, reason: pinReason });
|
||||||
// Priority 3: major behind without a pin reason — possible liability
|
// Priority 3: major behind without a pin reason — possible liability
|
||||||
} else if (isMajorBehind) {
|
} else if (isMajorBehind) {
|
||||||
tiers.majorBehindUnpinned.push(entry);
|
tiers.majorBehindUnpinned.push(entry);
|
||||||
// Priority 4: same major, minor/patch drift
|
// Priority 4: same major, minor/patch drift
|
||||||
} else {
|
} else {
|
||||||
tiers.routineDrift.push(entry);
|
tiers.routineDrift.push(entry);
|
||||||
}
|
}
|
||||||
@@ -141,13 +145,19 @@ console.log('=== DEPENDENCY HEALTH REPORT ===');
|
|||||||
console.log('');
|
console.log('');
|
||||||
|
|
||||||
// Tier 1: OUTDATED-WITH-ADVISORY (direct deps only — see WR-04 note in header)
|
// Tier 1: OUTDATED-WITH-ADVISORY (direct deps only — see WR-04 note in header)
|
||||||
console.log('[OUTDATED-WITH-ADVISORY] Outdated direct deps that also appear as an advisory subject');
|
console.log(
|
||||||
console.log(' (best-effort; most advisories are on transitive deps — authoritative gate is check-audit.mjs):');
|
'[OUTDATED-WITH-ADVISORY] Outdated direct deps that also appear as an advisory subject',
|
||||||
|
);
|
||||||
|
console.log(
|
||||||
|
' (best-effort; most advisories are on transitive deps — authoritative gate is check-audit.mjs):',
|
||||||
|
);
|
||||||
if (tiers.auditAdvisory.length === 0) {
|
if (tiers.auditAdvisory.length === 0) {
|
||||||
console.log(' (none)');
|
console.log(' (none)');
|
||||||
} else {
|
} else {
|
||||||
for (const pkg of tiers.auditAdvisory) {
|
for (const pkg of tiers.auditAdvisory) {
|
||||||
console.log(` ${pkg.name} ${pkg.current} → ${pkg.latest} (${pkg.dependencyType}) *** ADVISORY ON CURRENT VERSION ***`);
|
console.log(
|
||||||
|
` ${pkg.name} ${pkg.current} → ${pkg.latest} (${pkg.dependencyType}) *** ADVISORY ON CURRENT VERSION ***`,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
console.log('');
|
console.log('');
|
||||||
|
|||||||
Reference in New Issue
Block a user