Repository navigation
Replace vulnerable Lighthouse and publisher tooling with complete fresh audits - #27
Merged
systemslibrarian merged 3 commits intoOct 9, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The previous LHCI/gh-pages tooling retains vulnerable transitive packages, and the hosted runner exposed a queue-test observation race. Use pinned Lighthouse 13.5.0 directly, preserve the existing three-run accessibility gate and score-warning policy, and request the authoritative main deployment workflow from npm deploy.
Each quality invocation creates fresh evidence, rejects failed, stale, malformed, partial or unreadable reports, and retains failed manifests. The workflow uses the hosted runner system Chrome with its sandbox and explicitly uploads only the hidden .lighthouseci evidence directory. Job permissions and deploy prerequisites remain unchanged.
The queue browser test now installs its MutationObserver before navigation so it records fast measuring transitions. It still requires all four real panels, exclusive concurrency of exactly one, completed verdicts and enabled controls. A valid-build queue-bypass control observed concurrency three and failed; disabling observation also failed. Both fixtures were restored. An earlier fixture failed to build and is retained as inconclusive, not browser evidence.
Final reviewed commit: 3bacb3e. Node 24: npm ci, lint, 42 unit/DOM tests plus 5 native failure-path controls, build, all 16 browser cases, three actual Lighthouse audits, and npm audit (0 vulnerabilities) passed. Local disk exhaustion interrupted one quality attempt; after reclaiming only generated caches the complete fresh audits passed. Earlier Linux Chrome/artifact and queue-observation failures remain in the evidence history. Build and quality at this exact PR head must pass before merge; integrated main, deployment, uploaded audit artifacts and public application remain separate verification stages.
No cryptographic implementation or runtime dependency is changed. Historical Dependabot service BlobNotFound work caed46d4-875f-4295-b323-28c5bf6a59b6 remains blocked independently.