Skip to content

fix(ci): defer mutable dependency audits to the launch gate - #429

Open
sylphx-desk-studio[bot] wants to merge 5 commits into
mainfrom
fix/advisory-audit-ownership
Open

sylphx-desk-studio[bot] wants to merge 5 commits into
mainfrom
fix/advisory-audit-ownership

Conversation

@sylphx-desk-studio

Copy link
Copy Markdown
Contributor

What

Remove the mutable-registry dependency audit and its unused Bun setup from the PR Security Scan job. Retain the required job name and verified-secret detection unchanged. Pin shared workflow-lint to 77f1fd9da44cc1b382ca4cf24d8573cbda4564b2, which guards against direct package-manager audits returning to the pre-merge gate. Record the deferred launch audit checklist in the CI reference.

Why

The sharp advisory in GHSA-wq5f-xc86-pv6w failed an unchanged PR dependency: advisory publication is not a source regression. Unrelated PR authors must not repair the same trunk dependency repeatedly. During development, security audits are deferred to launch. At launch the existing dependency bot owns advisory repairs, and a separate daily default-branch audit owns detection, without feeding source-culprit automatic rollback or ci-ok.

This adopts the companion shared workflow-lint change. The queue entry is created after that exact shared action head is pushed, so the pinned object exists before CI resolves it.

How tested

  • git diff origin/main HEAD --check passed; native pre-commit hooks ran and skipped unrelated TypeScript checks.
  • The shared guard adds regression cases for package-manager commands across all pre-merge triggers, scheduled-only audits, comments, secret detection and delivered-customer exemptions.
  • Remote execution could not start because this worker has no Build org/project/env context. No local test pass is claimed. CI must run workflow parsing and the shared-action consumer invocation at the pinned SHA, then the repository's normal required gate.

No dependency-version, gameplay, authentication, database, schema or runtime change. Rollback is reverting the workflow and documentation change.

@sylphx-desk-studio sylphx-desk-studio Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The consumer removes the mutable registry audit while retaining verified-secret detection and the required job name; browser budgets remain enabled after merge and on schedules. The exact consumer head passed ci-ok. This adopts the action from companion pull request SylphxAI/.github#234, which is still unmerged and has failing checks; land its corrected, independently reviewed action first and repin this consumer if its SHA changes. No consumer code blockers found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant