§15: gate the dependency audit on the full tree - #6
Merged
Merged
Conversation
MichalAFerber
force-pushed
the
s15/audit-full-tree
branch
from
September 7, 2026 06:44
55be2ab to
468a65e
Compare
DS §15 (tgwab-standards v2.63.0, PR #159) reverses the audit gate: the full tree is the default and --omit=dev is now an exception needing a Deviations line. Drop the flag and fix the step comment, which stated the overturned reasoning. Measured before opening: this repo full-tree audit at --audit-level=high exits 0, as do all 16 repos carrying the gate. Zero expected findings. Closes MichalAFerber/tgwab-standards#164 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Drift remediation. Zero expected findings.
DS §15 changed in
tgwab-standardsv2.63.0 (PR MichalAFerber/tgwab-standards#159, merged 2026-09-07T06:04:12Z): the dependency audit MUST gate on the full tree, and--omit=dev/--prodis now an exception requiring a documented## Deviationsline — joining--audit-level=criticaland|| true, the two weakenings §15 already forbade.The step comment is updated with it. It read "Production tree only — a dev-tree advisory never reaches a user," which is the reasoning the ruling overturns; leaving that in place is how the flag comes back.
Why this is not expected to find anything
This repo's full-tree audit at
--audit-level=highexits 0 today — measured on its default-branch lockfile before this PR was opened, as were all 16 repos carrying the gate. The whole estate holds exactly one open advisory at any severity:GHSA-67mh-4wv8-2f99inesbuild, moderate, which is below thehighthreshold.So this is not a hunt. The value is that the standard and the estate agree, and that the gate stops being structurally unable to see the build toolchain. If CI does turn red here, that is a genuinely new advisory that landed since the measurement — measure it, do not suppress it to make this PR pass.
If this ever does turn red, note that npm has no per-advisory suppression —
npm auditoffers only--omit,--include, and--audit-level, and anauditConfigkey inpackage.jsonis not read (tested). Fix withoverridesfirst;--omit=devis now a documented## Deviationsline, not a default.This repo specifically
The gate here was auditing almost nothing. This repo declares zero runtime dependencies — everything is a devDependency — so
--omit=devleft 2 of 153 packages in scope. It could not have reported a finding regardless of what landed in the tree. That is a gate passing because it is blind, not because the tree is clean.Verification
ci.ymlre-parsed as YAML after the edit; the audit step resolves tonpm audit --audit-level=highand no--omit=dev/--prodremains.mainat branch time rather than trusted from the earlier sweep table — ~40 PRs merged estate-wide between the measurement and this PR.gh pr list --state allshows no prior PR for this change.Closes MichalAFerber/tgwab-standards#164
🤖 Generated with Claude Code
https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2