Skip to content

ci: gate pnpm audit on fixable advisories#89

Merged
dev-jodee merged 2 commits into
mainfrom
ci/use-pnpm-ignore-unfixable
May 21, 2026
Merged

ci: gate pnpm audit on fixable advisories#89
dev-jodee merged 2 commits into
mainfrom
ci/use-pnpm-ignore-unfixable

Conversation

@dev-jodee
Copy link
Copy Markdown
Collaborator

@dev-jodee dev-jodee commented May 21, 2026

Summary

  • replace the hard-coded pnpm audit advisory ignore with pnpm --ignore-unfixable
  • remove package.json auditConfig metadata from the earlier audit baseline
  • keep CI passing for current unpatched transitive advisories while failing on fixable ones

Test Plan

  • ruby YAML parse for .github/workflows/security.yml
  • git diff --check

@vercel
Copy link
Copy Markdown

vercel Bot commented May 21, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
solana-escrow-program Ready Ready Preview, Comment May 21, 2026 1:58pm

Request Review

@dev-jodee dev-jodee merged commit 4d6ebc6 into main May 21, 2026
10 checks passed
@dev-jodee dev-jodee deleted the ci/use-pnpm-ignore-unfixable branch May 21, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant