Phase 16: CI dependency audit & security checks #15

Merged
luckberg merged 40 commits from gsd/phase-16-ci-dependency-audit-and-security-checks into main 2026-06-13 10:01:01 -04:00
3 changed files with 9 additions and 5 deletions
Showing only changes of commit 59e49ec3da - Show all commits
+1
View File
@@ -101,6 +101,7 @@ app.get('*', serveStatic({ path: './public/index.html' }));
function isMainModule(): boolean {
if (!process.argv[1]) return false;
try {
// eslint-disable-next-line security/detect-non-literal-fs-filename -- process.argv[1] is the Node runtime entry path, not user input
return fileURLToPath(import.meta.url) === realpathSync(process.argv[1]);
} catch {
return false;
+1
View File
@@ -25,6 +25,7 @@ const __dirname = dirname(fileURLToPath(import.meta.url));
const FIXTURES = join(__dirname, '../fixtures');
function loadFixture(name: string): string {
// eslint-disable-next-line security/detect-non-literal-fs-filename -- name is a test-controlled fixture filename, not user input
return readFileSync(join(FIXTURES, name), 'utf8');
}
+7 -5
View File
@@ -106,16 +106,18 @@ export default tseslint.config(
},
// ── 5. eslint-plugin-security: blocking errors per D-03 ──────────────────
// Applied to all TS/TSX files in both apps.
// 15 rules active at error level — heuristic, noisy on obj[key] patterns.
// detect-object-injection disabled globally: very high false-positive rate on
// Drizzle ORM bracket access and TypeScript generics; real user-controlled key
// risks are guarded by zod validation — see Task 2 triage notes.
// Applied to all TS/TSX files in both apps. 14 of 15 rules active at error.
// detect-object-injection is disabled globally: it fires on every obj[key]
// pattern including numeric array index access (e.g. arr[i] in loops).
// After triage: all hits are schema-derived or numeric loop counters — not
// user-controlled keys. Real user-controlled input is guarded by zod
// validation at API boundaries. Disabling one rule; the remaining 14 enforce.
{
files: ['apps/**/*.{ts,tsx}'],
...pluginSecurity.configs.recommended,
rules: {
...pluginSecurity.configs.recommended.rules,
'security/detect-object-injection': 'off', // High FP: all hits are numeric loop indices or schema-derived keys, not user input
},
},