From 2b0a6b2b6cff87eec897ad760421b62c7243ff2e Mon Sep 17 00:00:00 2001 From: snekxs <26660858+snekxs@users.noreply.github.com> Date: Wed, 30 Sep 2026 15:23:18 -0600 Subject: [PATCH] ci: audit only the dependencies the package ships --- .github/workflows/ci.yml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e6d6a1c..86eb9fa 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -22,7 +22,12 @@ jobs: - run: npm ci - run: npm run build - run: npm pack --dry-run - - run: npm audit --audit-level=high + # Audit what the published package installs. The package ships no runtime + # dependencies, so this only ever reports advisories in code consumers + # would receive; release tooling (semantic-release pulls in npm, which + # bundles its own dependency tree) is deliberately excluded so a vuln in + # some other project's bundled CLI cannot block our releases. + - run: npm audit --omit=dev --audit-level=high # The suite is CPU-bound and runs serially (~6 min locally, ~11 min on a # runner), so it is sharded across jobs instead of one long run. Each shard