Skip to content

Replace vulnerable Lighthouse and publisher tooling with complete fresh audits - #27

Merged
systemslibrarian merged 3 commits into
mainfrom
repair/maintained-lighthouse-quality-20261009
Oct 9, 2026
Merged

systemslibrarian merged 3 commits into
mainfrom
repair/maintained-lighthouse-quality-20261009

Conversation

@systemslibrarian

@systemslibrarian systemslibrarian commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

The previous LHCI/gh-pages tooling retains vulnerable transitive packages, and the hosted runner exposed a queue-test observation race. Use pinned Lighthouse 13.5.0 directly, preserve the existing three-run accessibility gate and score-warning policy, and request the authoritative main deployment workflow from npm deploy.

Each quality invocation creates fresh evidence, rejects failed, stale, malformed, partial or unreadable reports, and retains failed manifests. The workflow uses the hosted runner system Chrome with its sandbox and explicitly uploads only the hidden .lighthouseci evidence directory. Job permissions and deploy prerequisites remain unchanged.

The queue browser test now installs its MutationObserver before navigation so it records fast measuring transitions. It still requires all four real panels, exclusive concurrency of exactly one, completed verdicts and enabled controls. A valid-build queue-bypass control observed concurrency three and failed; disabling observation also failed. Both fixtures were restored. An earlier fixture failed to build and is retained as inconclusive, not browser evidence.

Final reviewed commit: 3bacb3e. Node 24: npm ci, lint, 42 unit/DOM tests plus 5 native failure-path controls, build, all 16 browser cases, three actual Lighthouse audits, and npm audit (0 vulnerabilities) passed. Local disk exhaustion interrupted one quality attempt; after reclaiming only generated caches the complete fresh audits passed. Earlier Linux Chrome/artifact and queue-observation failures remain in the evidence history. Build and quality at this exact PR head must pass before merge; integrated main, deployment, uploaded audit artifacts and public application remain separate verification stages.

No cryptographic implementation or runtime dependency is changed. Historical Dependabot service BlobNotFound work caed46d4-875f-4295-b323-28c5bf6a59b6 remains blocked independently.

@systemslibrarian
systemslibrarian merged commit 8c6d94b into main Oct 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant