Skip to content

refactor: Add security scan for multiple scopes in CI workflow - #1640

Draft
d3xter666 wants to merge 6 commits into
mainfrom
refactor-security-audit
Draft

d3xter666 wants to merge 6 commits into
mainfrom
refactor-security-audit

Conversation

@d3xter666

Copy link
Copy Markdown
Member

Why audit three ways, not one

The workflow runs the audit from three angles, to separate what we tested from what users get from our full dev surface:

Variant Install Scope Answers
locked · ci npm ci dev + prod What our committed package-lock.json pins — the reproducible tree we build & test against.
latest · prod only fresh npm install, --skip-dev prod What a new @ui5/cli install gives users today. The one that matters most.
latest · dev + prod fresh npm install dev + prod What the whole repo pulls in at latest, incl. our tooling — early warning across everything.

Goal: catch advisories that reach users (or our build) before Dependabot does, and know which bucket each finding sits in so we can prioritize. Each variant runs independently (fail-fast: false), so one failing never hides the others.

@d3xter666
d3xter666 marked this pull request as draft October 8, 2026 06:28
Comment thread .github/workflows/security-audit.yml Fixed
Comment thread .github/workflows/security-audit.yml Fixed

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants