From 49dbb427ab9c592ee86f4b45f28d2f8b93e27115 Mon Sep 17 00:00:00 2001 From: Michal Ferber Date: Mon, 7 Sep 2026 02:43:59 -0400 Subject: [PATCH] =?UTF-8?q?=C2=A715:=20gate=20the=20dependency=20audit=20o?= =?UTF-8?q?n=20the=20full=20tree?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit DS §15 (tgwab-standards v2.63.0, PR #159) reverses the audit gate: the full tree is the default and --omit=dev is now an exception needing a Deviations line. Drop the flag and fix the step comment, which stated the overturned reasoning. Measured before opening: this repo full-tree audit at --audit-level=high exits 0, as do all 16 repos carrying the gate. Zero expected findings. Closes MichalAFerber/tgwab-standards#164 Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2 --- .github/workflows/ci.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 51a0b7c..6b874f6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -117,5 +117,8 @@ jobs: fi npm test - # Production tree only—a dev-tree advisory never reaches a user (§15). - - run: npm audit --omit=dev --audit-level=high + # Full tree, deliberately not --omit=dev (DS §15): the dev half is the + # build toolchain, and what it writes into dist/ is what ships. Excluding it + # blinds the gate to the half whose compromise reaches users. Narrowing this + # is now a documented `## Deviations` line, not a default. + - run: npm audit --audit-level=high