mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 06:33:16 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs 10.27.2, and brace-expansion 1.1.16 to clear four high DoS advisories. Eleventy build verified passing at 3.1.6. The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has no in-range fix: the patch exists only in 5.0.8, and @11ty/recursive-copy pins an older minimatch. Exposure is build-time only (glob patterns from our own config, never untrusted input), so it is suppressed with justification in .security-review/suppressions.json rather than forcing the eleventy downgrade npm audit fix --force proposes. Remove the npmaudit-* suppressions when recursive-copy ships a minimatch >=10.0.3 bump. * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match. * ci(dependency-review): allow adjudicated brace-expansion GHSA Re-pins the callable to 07ce007 (adds the allow-ghsas input, org PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check flags on the bumped-but-still-in-range brace-expansion 1.1.16. The advisory has no in-range fix and is an accepted risk with written justification in .security-review/suppressions.json; remove the allowance together with those suppressions when @11ty/recursive-copy ships a minimatch >=10.0.3 bump.
16 lines
536 B
YAML
16 lines
536 B
YAML
name: Dependency Review
|
|
|
|
on:
|
|
pull_request:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
review:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@07ce007bad08fdcf07409a5f372baabda8781354 # main
|
|
with:
|
|
# brace-expansion OOM DoS: no in-range fix (patch only in 5.0.8; @11ty/recursive-copy
|
|
# pins minimatch <10.0.3). Build-time-only exposure, adjudicated in
|
|
# .security-review/suppressions.json — remove when recursive-copy bumps minimatch.
|
|
allow-ghsas: GHSA-mh99-v99m-4gvg
|