style(16): apply prettier formatting to satisfy CI format:check
CI / changes (pull_request) Successful in 2s
CI / fast-checks (pull_request) Successful in 1m23s
CI / api (pull_request) Successful in 1m0s
CI / harness (pull_request) Successful in 3m54s
CI / security (pull_request) Successful in 40s
CI / gate (pull_request) Successful in 1s

This commit is contained in:
Lucas Berger
2026-06-13 09:29:02 -04:00
parent c72e013a7b
commit 8154ba6f35
4 changed files with 32 additions and 28 deletions
+1 -1
View File
@@ -352,7 +352,7 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
with: with:
fetch-depth: 0 # Required: base.sha must be locally available for git log range (Pitfall 3) fetch-depth: 0 # Required: base.sha must be locally available for git log range (Pitfall 3)
# ── Probe PR base/head SHA with merge-base fallback (A2 / OQ-1) ────────── # ── Probe PR base/head SHA with merge-base fallback (A2 / OQ-1) ──────────
# github.event.pull_request.base.sha may be empty on some Gitea versions. # github.event.pull_request.base.sha may be empty on some Gitea versions.
+9 -15
View File
@@ -28,11 +28,9 @@ describe('assertNotDevBypassInProduction', () => {
process.env.NODE_ENV = 'production'; process.env.NODE_ENV = 'production';
process.env.DEV_AUTH_BYPASS = 'true'; process.env.DEV_AUTH_BYPASS = 'true';
const exitSpy = vi const exitSpy = vi.spyOn(process, 'exit').mockImplementation((() => {
.spyOn(process, 'exit') throw new Error('process.exit called');
.mockImplementation((() => { }) as never);
throw new Error('process.exit called');
}) as never);
expect(() => assertNotDevBypassInProduction()).toThrow('process.exit called'); expect(() => assertNotDevBypassInProduction()).toThrow('process.exit called');
expect(exitSpy).toHaveBeenCalledWith(1); expect(exitSpy).toHaveBeenCalledWith(1);
@@ -44,11 +42,9 @@ describe('assertNotDevBypassInProduction', () => {
process.env.NODE_ENV = 'development'; process.env.NODE_ENV = 'development';
process.env.DEV_AUTH_BYPASS = 'true'; process.env.DEV_AUTH_BYPASS = 'true';
const exitSpy = vi const exitSpy = vi.spyOn(process, 'exit').mockImplementation((() => {
.spyOn(process, 'exit') throw new Error('process.exit called');
.mockImplementation((() => { }) as never);
throw new Error('process.exit called');
}) as never);
expect(() => assertNotDevBypassInProduction()).not.toThrow(); expect(() => assertNotDevBypassInProduction()).not.toThrow();
expect(exitSpy).not.toHaveBeenCalled(); expect(exitSpy).not.toHaveBeenCalled();
@@ -60,11 +56,9 @@ describe('assertNotDevBypassInProduction', () => {
process.env.NODE_ENV = 'production'; process.env.NODE_ENV = 'production';
delete process.env.DEV_AUTH_BYPASS; delete process.env.DEV_AUTH_BYPASS;
const exitSpy = vi const exitSpy = vi.spyOn(process, 'exit').mockImplementation((() => {
.spyOn(process, 'exit') throw new Error('process.exit called');
.mockImplementation((() => { }) as never);
throw new Error('process.exit called');
}) as never);
expect(() => assertNotDevBypassInProduction()).not.toThrow(); expect(() => assertNotDevBypassInProduction()).not.toThrow();
expect(exitSpy).not.toHaveBeenCalled(); expect(exitSpy).not.toHaveBeenCalled();
+4 -4
View File
@@ -14,7 +14,7 @@ import { selectBlocking, partitionAdvisories, isWaived } from '../check-audit.mj
// Fixture: a High advisory not in the allowlist // Fixture: a High advisory not in the allowlist
const highUnwaived = { const highUnwaived = {
'1': { 1: {
severity: 'high', severity: 'high',
github_advisory_id: 'GHSA-test-unwaived-high', github_advisory_id: 'GHSA-test-unwaived-high',
module_name: 'some-package', module_name: 'some-package',
@@ -24,7 +24,7 @@ const highUnwaived = {
// Fixture: a High advisory that IS in the allowlist // Fixture: a High advisory that IS in the allowlist
const highWaived = { const highWaived = {
'2': { 2: {
severity: 'high', severity: 'high',
github_advisory_id: 'GHSA-gv7w-rqvm-qjhr', github_advisory_id: 'GHSA-gv7w-rqvm-qjhr',
module_name: 'esbuild', module_name: 'esbuild',
@@ -34,13 +34,13 @@ const highWaived = {
// Fixture: only moderate/low advisories // Fixture: only moderate/low advisories
const moderateLow = { const moderateLow = {
'3': { 3: {
severity: 'moderate', severity: 'moderate',
github_advisory_id: 'GHSA-mod-erate-test', github_advisory_id: 'GHSA-mod-erate-test',
module_name: 'another-package', module_name: 'another-package',
title: 'Moderate vulnerability', title: 'Moderate vulnerability',
}, },
'4': { 4: {
severity: 'low', severity: 'low',
github_advisory_id: 'GHSA-low-test-only', github_advisory_id: 'GHSA-low-test-only',
module_name: 'yet-another', module_name: 'yet-another',
+18 -8
View File
@@ -62,7 +62,9 @@ try {
pins = JSON.parse(readFileSync(pinsPath, 'utf8')); pins = JSON.parse(readFileSync(pinsPath, 'utf8'));
} catch { } catch {
// Gracefully degrade — no pins means everything is treated as unpinned // Gracefully degrade — no pins means everything is treated as unpinned
console.warn('[check-outdated] Warning: could not read outdated-pins.json; treating all pins as unknown'); console.warn(
'[check-outdated] Warning: could not read outdated-pins.json; treating all pins as unknown',
);
} }
// ── Run pnpm audit to collect vulnerable module names ─────────────────────── // ── Run pnpm audit to collect vulnerable module names ───────────────────────
@@ -78,7 +80,9 @@ try {
} }
} catch { } catch {
// Audit parse failure is non-fatal for the outdated report // Audit parse failure is non-fatal for the outdated report
console.warn('[check-outdated] Warning: could not parse pnpm audit output; OUTDATED-WITH-ADVISORY cross-check skipped'); console.warn(
'[check-outdated] Warning: could not parse pnpm audit output; OUTDATED-WITH-ADVISORY cross-check skipped',
);
} }
// ── Run pnpm outdated ──────────────────────────────────────────────────────── // ── Run pnpm outdated ────────────────────────────────────────────────────────
@@ -123,13 +127,13 @@ for (const [pkgName, info] of Object.entries(outdatedData)) {
// file header); the authoritative advisory gate is check-audit.mjs. // file header); the authoritative advisory gate is check-audit.mjs.
if (hasAdvisory) { if (hasAdvisory) {
tiers.auditAdvisory.push(entry); tiers.auditAdvisory.push(entry);
// Priority 2: major behind + intentional pin // Priority 2: major behind + intentional pin
} else if (isMajorBehind && pinReason) { } else if (isMajorBehind && pinReason) {
tiers.majorBehindIntentional.push({ ...entry, reason: pinReason }); tiers.majorBehindIntentional.push({ ...entry, reason: pinReason });
// Priority 3: major behind without a pin reason — possible liability // Priority 3: major behind without a pin reason — possible liability
} else if (isMajorBehind) { } else if (isMajorBehind) {
tiers.majorBehindUnpinned.push(entry); tiers.majorBehindUnpinned.push(entry);
// Priority 4: same major, minor/patch drift // Priority 4: same major, minor/patch drift
} else { } else {
tiers.routineDrift.push(entry); tiers.routineDrift.push(entry);
} }
@@ -141,13 +145,19 @@ console.log('=== DEPENDENCY HEALTH REPORT ===');
console.log(''); console.log('');
// Tier 1: OUTDATED-WITH-ADVISORY (direct deps only — see WR-04 note in header) // Tier 1: OUTDATED-WITH-ADVISORY (direct deps only — see WR-04 note in header)
console.log('[OUTDATED-WITH-ADVISORY] Outdated direct deps that also appear as an advisory subject'); console.log(
console.log(' (best-effort; most advisories are on transitive deps — authoritative gate is check-audit.mjs):'); '[OUTDATED-WITH-ADVISORY] Outdated direct deps that also appear as an advisory subject',
);
console.log(
' (best-effort; most advisories are on transitive deps — authoritative gate is check-audit.mjs):',
);
if (tiers.auditAdvisory.length === 0) { if (tiers.auditAdvisory.length === 0) {
console.log(' (none)'); console.log(' (none)');
} else { } else {
for (const pkg of tiers.auditAdvisory) { for (const pkg of tiers.auditAdvisory) {
console.log(` ${pkg.name} ${pkg.current}${pkg.latest} (${pkg.dependencyType}) *** ADVISORY ON CURRENT VERSION ***`); console.log(
` ${pkg.name} ${pkg.current}${pkg.latest} (${pkg.dependencyType}) *** ADVISORY ON CURRENT VERSION ***`,
);
} }
} }
console.log(''); console.log('');