Skip to content

ci: audit only the dependencies the package ships - #149

Merged
snekxs merged 1 commit into
mainfrom
fix/audit-shipped-deps
Sep 30, 2026
Merged

snekxs merged 1 commit into
mainfrom
fix/audit-shipped-deps

Conversation

@snekxs

@snekxs snekxs commented Sep 30, 2026

Copy link
Copy Markdown
Member

The build job has been failing on npm audit for everyone since new advisories landed against undici, ip-address and brace-expansion — but those are the copies bundled inside npm itself, pulled in by semantic-release. No released npm (11.x or 12.x) ships a patched copy yet, and overrides cannot reach a bundled dependency tree, so this blocks every protocol release and, through it, every dependent OpenMouse PR.

This package publishes no runtime dependencies, so audit what consumers actually install (--omit=dev) rather than release-only tooling. A production dependency added later is still audited.

@snekxs
snekxs merged commit a70f27a into main Sep 30, 2026
10 checks passed
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 0.20.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant