Skip to content

§15: gate the dependency audit on the full tree - #6

Merged
MichalAFerber merged 1 commit into
mainfrom
s15/audit-full-tree
Sep 7, 2026
Merged

MichalAFerber merged 1 commit into
mainfrom
s15/audit-full-tree

Conversation

@MichalAFerber

Copy link
Copy Markdown
Member

Drift remediation. Zero expected findings.

DS §15 changed in tgwab-standards v2.63.0 (PR MichalAFerber/tgwab-standards#159, merged 2026-09-07T06:04:12Z): the dependency audit MUST gate on the full tree, and --omit=dev / --prod is now an exception requiring a documented ## Deviations line — joining --audit-level=critical and || true, the two weakenings §15 already forbade.

-npm audit --omit=dev --audit-level=high
+npm audit --audit-level=high

The step comment is updated with it. It read "Production tree only — a dev-tree advisory never reaches a user," which is the reasoning the ruling overturns; leaving that in place is how the flag comes back.

Why this is not expected to find anything

This repo's full-tree audit at --audit-level=high exits 0 today — measured on its default-branch lockfile before this PR was opened, as were all 16 repos carrying the gate. The whole estate holds exactly one open advisory at any severity: GHSA-67mh-4wv8-2f99 in esbuild, moderate, which is below the high threshold.

So this is not a hunt. The value is that the standard and the estate agree, and that the gate stops being structurally unable to see the build toolchain. If CI does turn red here, that is a genuinely new advisory that landed since the measurement — measure it, do not suppress it to make this PR pass.

If this ever does turn red, note that npm has no per-advisory suppression — npm audit offers only --omit, --include, and --audit-level, and an auditConfig key in package.json is not read (tested). Fix with overrides first; --omit=dev is now a documented ## Deviations line, not a default.

This repo specifically

The gate here was auditing almost nothing. This repo declares zero runtime dependencies — everything is a devDependency — so --omit=dev left 2 of 153 packages in scope. It could not have reported a finding regardless of what landed in the tree. That is a gate passing because it is blind, not because the tree is clean.

Verification

  • ci.yml re-parsed as YAML after the edit; the audit step resolves to npm audit --audit-level=high and no --omit=dev / --prod remains.
  • Current spelling re-checked on main at branch time rather than trusted from the earlier sweep table — ~40 PRs merged estate-wide between the measurement and this PR.
  • Rule 6, both halves: no worktree in this repo holds audit-gate work, and gh pr list --state all shows no prior PR for this change.

Closes MichalAFerber/tgwab-standards#164

🤖 Generated with Claude Code

https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2

DS §15 (tgwab-standards v2.63.0, PR #159) reverses the audit gate: the full
tree is the default and --omit=dev is now an exception needing a Deviations
line. Drop the flag and fix the step comment, which stated the overturned
reasoning.

Measured before opening: this repo full-tree audit at --audit-level=high
exits 0, as do all 16 repos carrying the gate. Zero expected findings.

Closes MichalAFerber/tgwab-standards#164

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2
@MichalAFerber MichalAFerber reopened this Sep 7, 2026
@MichalAFerber
MichalAFerber marked this pull request as ready for review September 7, 2026 06:56
@MichalAFerber
MichalAFerber merged commit 2d82c67 into main Sep 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant