Skip to content

fix(ci): npm audit failure reddens Security Scanning repo-wide and silently skips gosec + Trivy #1712

Description

@cristim

Two newly published high-severity npm advisories now fail npm audit --audit-level=high in frontend/, which reddens Security Scanning on every PR and on main. Reproduced against origin/main at 02702a108:

brace-expansion  4.0.0 - 5.0.8   high
  DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
  https://github.com/advisories/GHSA-rgw5-rvv9-x895

fast-uri  3.0.0 - 3.1.4          high
  host confusion via backslash authority introducer
  https://github.com/advisories/GHSA-7p8r-x3mc-p8w7

2 high severity vulnerabilities
exit=1

Both are transitive dependencies and both report fix available via npm audit fix.

This is time-dependent, not caused by any PR. npm audit queries the live advisory database, so the same commit passes or fails depending on when CI runs. Security Scanning passed on #1657 at 16:39:46Z, #1658 at 16:45:57Z and #1710 at 17:07:11Z, then failed on #1711 at roughly 21:00Z. Nothing in those PRs touches the frontend.

The more serious half: one failing step disables the Go and IaC scanners

.github/workflows/ci.yml:317-321 runs npm audit as step 5 of the Security Scanning job. When it exits non-zero, every later scanner in the same job is skipped:

4. Run govulncheck CVE scanner (all modules)  -> success
5. Run npm audit (frontend)                   -> FAILURE
6. Run gosec Security Scanner                 -> skipped
7. Upload gosec results to GitHub Security    -> failure   (no gosec-results.sarif)
8. Run Trivy vulnerability scanner (fs)       -> skipped
9. Upload Trivy results                       -> skipped
10. Run Trivy IaC misconfiguration scanner    -> skipped
11. Upload Trivy IaC results                  -> failure   (no trivy-config-results.sarif)

So a frontend JavaScript advisory silently turns off Go SAST and Terraform IaC misconfiguration scanning for the whole repo. The two failure entries at steps 7 and 11 are missing-SARIF artefacts, which is a misleading symptom: the annotations read Path does not exist: gosec-results.sarif, pointing at the upload rather than the cause.

This matters beyond the current advisories. Any future frontend advisory, or any transient npm registry error, disables the security scanners that cover the money-path Go code and the IAM/Terraform definitions, while presenting as a single red check that a reader is likely to attribute to whatever they were touching.

Suggested fix

Two separable changes; the second is the one that keeps mattering after these advisories are patched.

  1. Patch the advisories. npm audit fix in frontend/, restricted to the lockfile if possible so no direct dependency ranges move. Confirm npm audit --audit-level=high exits 0 and the frontend build and tests still pass.
  2. Decouple the scanners. The Go, IaC and JavaScript scanners should not be able to disable one another. Either split them into separate jobs, or ensure each scanner step runs regardless of its predecessors' outcome while still failing the job overall. Do not suppress the npm failure to make the job green: the goal is that a real npm finding is still reported, and gosec and Trivy still run.

Do not gate this behind an only-new-issues-style filter or otherwise mask the debt. Fix the advisories and the coupling.

Found while diagnosing a Security Scanning failure on #1711, which turned out to be unrelated to that PR's changes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions