Repository navigation
ci: bump axios to 1.20.0 and audit production dependencies - #47
Conversation
The step is named for runtime dependencies but was auditing the full tree. Pass --omit=dev and keep --audit-level=moderate so dev-only advisories drop out and production advisories still fail the build. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 935bfcf16e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| run: npm run lint:markdown | ||
| - name: Audit runtime dependencies | ||
| run: npm audit --audit-level=moderate | ||
| run: npm audit --omit=dev --audit-level=moderate |
There was a problem hiding this comment.
Update the documented audit command with the workflow
When a moderate-or-higher advisory affects only a development dependency, this workflow can now pass while the command in CONTRIBUTING.md:13-18, explicitly described as one of the “same checks required by CI,” still fails because it lacks --omit=dev (npm audit --help documents dev as an accepted --omit dependency type). Update that command alongside the workflow so contributors can reproduce the required CI audit locally.
Useful? React with 👍 / 👎.
Regenerate the lockfile with npm update axios so the production tree matches Dependabot #46. No other locked versions change. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Pull Request
Summary
Audit runtime dependenciesstep runsnpm audit --omit=dev --audit-level=moderate, and the lockfile resolvesaxios1.20.0 (the same change as Dependabot build(deps): bump axios from 1.18.1 to 1.20.0 in the npm_and_yarn group across 1 directory #46).The full-tree audit still fails on GHSA-vfj7-8cjw-p6xm (
braces<= 3.0.3, high, CVE-2026-93687).first_patched_versionis null, andbraces3.0.3 is the latest release on npm, so no bump or override can fix it.bracesis dev-only, reached throughmarkdownlint-cli20.23.3 (latest) viamicromatch4.0.8, and viaglobby16.2.4 ->fast-glob3.3.3 ->micromatch. The step name matches the command. The audit level stays at moderate and nothing is ignored, so a future runtime advisory still fails CI.Lockfile version delta
axios(node_modules/axios)No other locked package version changed.
npm update axiosalso rewrote theform-dataspecifier inside the axios entry from^4.0.5to^4.0.6(axios 1.20.0's own manifest). The lockedform-datapackage stays 4.0.6.package.jsonis unchanged.Verification
Local commands on this tip (Node v22.14.0, npm 10.9.7), after
npm update axios:npm ci --ignore-scripts— exit 0. Added 151 packages.npm ciprinted the full-tree summary (9 vulnerabilities: 3 low, 1 moderate, 5 high) and exited 0.npm run check— exit 0. 20 tests, 20 pass, 0 fail.npm run lint:markdown— exit 0. markdownlint-cli2 v0.23.3 (markdownlint v0.41.1), 9 files, 0 issues.npm audit --omit=dev --audit-level=moderate— exit 0.found 0 vulnerabilities.npm audit --audit-level=moderate— exit 1 (dev-only; not the CI step). Output:npm audit --omit=dev --audit-level=moderateexits 0; repository validator runs in CI)CHANGELOG.md(no user-visible change)Security impact
Production
axiosmoves from 1.18.1 to 1.20.0, clearing the high runtime advisories that failed CI on 1.18.1. The runtime audit omits dev dependencies and still uses--audit-level=moderatewith nothing ignored. Dev-only advisories (braces,katex,smol-toml) remain in a fullnpm auditand do not fail the runtime step. Authentication, port exposure, command execution, protocol parsing, output handling, services, and licensing are unchanged.