mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 04:13:15 +00:00
|
Some checks are pending
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs 10.27.2, and brace-expansion 1.1.16 to clear four high DoS advisories. Eleventy build verified passing at 3.1.6. The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has no in-range fix: the patch exists only in 5.0.8, and @11ty/recursive-copy pins an older minimatch. Exposure is build-time only (glob patterns from our own config, never untrusted input), so it is suppressed with justification in .security-review/suppressions.json rather than forcing the eleventy downgrade npm audit fix --force proposes. Remove the npmaudit-* suppressions when recursive-copy ships a minimatch >=10.0.3 bump. * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match. * ci(dependency-review): allow adjudicated brace-expansion GHSA Re-pins the callable to 07ce007 (adds the allow-ghsas input, org PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check flags on the bumped-but-still-in-range brace-expansion 1.1.16. The advisory has no in-range fix and is an accepted risk with written justification in .security-review/suppressions.json; remove the allowance together with those suppressions when @11ty/recursive-copy ships a minimatch >=10.0.3 bump. |
||
|---|---|---|
| .. | ||
| ci.yaml | ||
| dependency-review.yml | ||
| deploy.yaml | ||
| labeler.yml | ||