Skip to content

feat(ts): ratcheted npm audit for the audit verb - #31

Merged
CMaintz merged 1 commit into
mainfrom
feat/ratcheted-npm-audit
Sep 29, 2026
Merged

CMaintz merged 1 commit into
mainfrom
feat/ratcheted-npm-audit

Conversation

@CMaintz

@CMaintz CMaintz commented Sep 29, 2026

Copy link
Copy Markdown
Owner

npm audit is all-or-nothing — a repo with one pre-existing, genuinely-unfixable critical either reds every PR or silences the whole check (neither acceptable per foundry's never silence the whole check).

scripts/npm-audit-ratchet.mjs adds a shrink-only allowlist, like eslint suppressions or the habit-hooks snooze baseline:

  • fails on any critical not in .audit-allowlist.json
  • fails on stale entries (the advisory is gone → prune it)
  • with no allowlist, behaves like plain npm audit --audit-level=critical

Wiring

  • mise/ts.toml audit pipes npm audit --json into the script (the pipe means npm resolves in the caller's shell — execSync-spawning-npm.cmd was flaky under mise on Windows).
  • foundry-init fetches it for the ts stack.
  • FEATURES.md documents it.

Exercised

  • clean report → exit 0; one un-accepted critical → exit 1; stale entry → exit 1.
  • Proven in the AutoApplicant frontend (jobbuddy#154): let a real tar critical be fixed via a targeted overrides entry (empty allowlist) instead of baselined.

npm audit is all-or-nothing — a repo with one pre-existing, genuinely unfixable
critical either reds every PR or silences the whole check. scripts/npm-audit-ratchet.mjs
adds a shrink-only allowlist (like eslint suppressions / the snooze baseline):
fails on any critical NOT in .audit-allowlist.json AND on stale entries, so accepted
CVE debt can only shrink. With no allowlist it behaves like plain
`npm audit --audit-level=critical`.

- mise/ts.toml `audit` pipes `npm audit --json` into the script (npm resolves in the
  shell; execSync-spawning-npm was flaky under mise on Windows).
- foundry-init fetches the script for the ts stack.
- FEATURES.md documents it.

Proven in the AutoApplicant frontend, where it let a real tar critical be fixed via a
targeted override (empty allowlist) rather than baselined.
@CMaintz
CMaintz merged commit 760c0e0 into main Sep 29, 2026
4 checks passed
@CMaintz
CMaintz deleted the feat/ratcheted-npm-audit branch September 30, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant