mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 01:29:56 +00:00
* fix(release): record dependency advisories without blocking releases Release dependency evidence now blocks only on known malware. Vulnerability advisories of every severity are recorded in the evidence summary and surfaced as GitHub warning annotations, and CI dispatched by Full Release Validation or release publication reports a failing production audit as a warning. The per-release risk-acceptance table existed only to accept advisory blockers and is removed. The release skills also record that main CI health never gates a release and that every failed test gets an explicit real-blocker-or-flake decision. * fix(ci): keep release audit relaxation within the workflow size budget ci.yml sits at the 480000-byte guard, so the release-dispatch check moves into a trusted harness script that security-fast already checks out.
40 lines
1.4 KiB
JavaScript
40 lines
1.4 KiB
JavaScript
#!/usr/bin/env node
|
|
|
|
// Runs the target's production dependency audit for CI's security-fast job.
|
|
// Trusted harness code: CI dispatched by release validation or publication records a
|
|
// failing audit as a warning, because dependency advisories never block a release.
|
|
import { spawnSync } from "node:child_process";
|
|
import { readFileSync } from "node:fs";
|
|
import process from "node:process";
|
|
|
|
const RELEASE_DISPATCH_PREFIXES = ["full-release-validation-", "release-native-android-"];
|
|
|
|
function isReleaseDispatch() {
|
|
if (process.env.GITHUB_EVENT_NAME !== "workflow_dispatch" || !process.env.GITHUB_EVENT_PATH) {
|
|
return false;
|
|
}
|
|
try {
|
|
const dispatchId = JSON.parse(readFileSync(process.env.GITHUB_EVENT_PATH, "utf8")).inputs
|
|
?.dispatch_id;
|
|
return (
|
|
typeof dispatchId === "string" &&
|
|
RELEASE_DISPATCH_PREFIXES.some((prefix) => dispatchId.startsWith(prefix))
|
|
);
|
|
} catch {
|
|
return false;
|
|
}
|
|
}
|
|
|
|
const audit = spawnSync(
|
|
process.execPath,
|
|
["scripts/pre-commit/pnpm-audit-prod.mjs", "--audit-level=high"],
|
|
{ stdio: "inherit" },
|
|
);
|
|
const status = audit.status ?? 1;
|
|
const nonBlocking = status !== 0 && isReleaseDispatch();
|
|
if (nonBlocking) {
|
|
process.stdout.write(
|
|
`::warning title=Dependency advisories do not block releases::Production dependency audit exited ${status}. Release CI records this without failing; queue the dependency bump on main after publication.\n`,
|
|
);
|
|
}
|
|
process.exitCode = nonBlocking ? 0 : status;
|