openclaw/scripts/ci-production-audit.mjs
Peter Steinberger 56f616e437
fix(release): dependency advisories no longer fail or delay a release (#161463)
* fix(release): record dependency advisories without blocking releases

Release dependency evidence now blocks only on known malware. Vulnerability
advisories of every severity are recorded in the evidence summary and surfaced
as GitHub warning annotations, and CI dispatched by Full Release Validation or
release publication reports a failing production audit as a warning. The
per-release risk-acceptance table existed only to accept advisory blockers and
is removed.

The release skills also record that main CI health never gates a release and
that every failed test gets an explicit real-blocker-or-flake decision.

* fix(ci): keep release audit relaxation within the workflow size budget

ci.yml sits at the 480000-byte guard, so the release-dispatch check moves
into a trusted harness script that security-fast already checks out.
2026-09-30 01:11:12 +00:00

40 lines
1.4 KiB
JavaScript

#!/usr/bin/env node
// Runs the target's production dependency audit for CI's security-fast job.
// Trusted harness code: CI dispatched by release validation or publication records a
// failing audit as a warning, because dependency advisories never block a release.
import { spawnSync } from "node:child_process";
import { readFileSync } from "node:fs";
import process from "node:process";
const RELEASE_DISPATCH_PREFIXES = ["full-release-validation-", "release-native-android-"];
function isReleaseDispatch() {
if (process.env.GITHUB_EVENT_NAME !== "workflow_dispatch" || !process.env.GITHUB_EVENT_PATH) {
return false;
}
try {
const dispatchId = JSON.parse(readFileSync(process.env.GITHUB_EVENT_PATH, "utf8")).inputs
?.dispatch_id;
return (
typeof dispatchId === "string" &&
RELEASE_DISPATCH_PREFIXES.some((prefix) => dispatchId.startsWith(prefix))
);
} catch {
return false;
}
}
const audit = spawnSync(
process.execPath,
["scripts/pre-commit/pnpm-audit-prod.mjs", "--audit-level=high"],
{ stdio: "inherit" },
);
const status = audit.status ?? 1;
const nonBlocking = status !== 0 && isReleaseDispatch();
if (nonBlocking) {
process.stdout.write(
`::warning title=Dependency advisories do not block releases::Production dependency audit exited ${status}. Release CI records this without failing; queue the dependency bump on main after publication.\n`,
);
}
process.exitCode = nonBlocking ? 0 : status;