mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-10-03 12:47:49 +00:00
On 30 Sep-1 Oct 2026 GHSA-q2hr-2g5m-vwhr (brace-expansion) and GHSA-p98j-92pf-mc4p (DOMPurify) failed the required "Audit complete frontend dependency graph" step on every pull request to main, release/v6.4 and release/v6.5. That held the v6.4.6 preparation PR and the v6.5 RC for days with no owner. The scheduled audit in security-scan.yml only informs and runs on the default branch, so release lines were never checked. dependency-advisory-watch.yml runs daily and on dispatch. It lists main plus every release/v<major>.<minor> line at or newer than the latest stable's line (all lines if that lookup fails), then audits each in a fail-fast-free matrix. Each job fetches only that line's frontend-modern/package.json and package-lock.json with git and runs scripts/npm-audit-retry.sh all on them under the same Node.js pin that build-and-test requires. npm audit reads the lockfile, so nothing is installed. The job never checks out or runs the audited branch's code, because a scheduled run holds the default branch's cache scope and CodeQL flagged running npm ci there as cache poisoning. A job fails when the audit fails, and its step summary and annotation name the branch, the GHSA ids and the fix (npm audit fix --package-lock-only plus raised floors in dependencySecurity.test.ts). Read-only, hosted-only, no secrets, no uploads. |
||
|---|---|---|
| .. | ||
| codeql/extensions/pulse-security-models | ||
| ISSUE_TEMPLATE | ||
| scripts | ||
| workflows | ||
| dependabot.yml | ||
| FUNDING.yml | ||
| PULL_REQUEST_TEMPLATE.md | ||
| v6_rc_feedback_hub.md | ||