feat(ts): ratcheted npm audit for the audit verb - #31
Merged
Merged
Conversation
npm audit is all-or-nothing — a repo with one pre-existing, genuinely unfixable critical either reds every PR or silences the whole check. scripts/npm-audit-ratchet.mjs adds a shrink-only allowlist (like eslint suppressions / the snooze baseline): fails on any critical NOT in .audit-allowlist.json AND on stale entries, so accepted CVE debt can only shrink. With no allowlist it behaves like plain `npm audit --audit-level=critical`. - mise/ts.toml `audit` pipes `npm audit --json` into the script (npm resolves in the shell; execSync-spawning-npm was flaky under mise on Windows). - foundry-init fetches the script for the ts stack. - FEATURES.md documents it. Proven in the AutoApplicant frontend, where it let a real tar critical be fixed via a targeted override (empty allowlist) rather than baselined.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
npm auditis all-or-nothing — a repo with one pre-existing, genuinely-unfixable critical either reds every PR or silences the whole check (neither acceptable per foundry's never silence the whole check).scripts/npm-audit-ratchet.mjsadds a shrink-only allowlist, like eslint suppressions or the habit-hooks snooze baseline:.audit-allowlist.jsonnpm audit --audit-level=criticalWiring
mise/ts.tomlauditpipesnpm audit --jsoninto the script (the pipe meansnpmresolves in the caller's shell — execSync-spawning-npm.cmdwas flaky under mise on Windows).foundry-initfetches it for thetsstack.FEATURES.mddocuments it.Exercised
tarcritical be fixed via a targetedoverridesentry (empty allowlist) instead of baselined.