Two newly published high-severity npm advisories now fail npm audit --audit-level=high in frontend/, which reddens Security Scanning on every PR and on main. Reproduced against origin/main at 02702a108:
brace-expansion 4.0.0 - 5.0.8 high
DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
https://github.com/advisories/GHSA-rgw5-rvv9-x895
fast-uri 3.0.0 - 3.1.4 high
host confusion via backslash authority introducer
https://github.com/advisories/GHSA-7p8r-x3mc-p8w7
2 high severity vulnerabilities
exit=1
Both are transitive dependencies and both report fix available via npm audit fix.
This is time-dependent, not caused by any PR. npm audit queries the live advisory database, so the same commit passes or fails depending on when CI runs. Security Scanning passed on #1657 at 16:39:46Z, #1658 at 16:45:57Z and #1710 at 17:07:11Z, then failed on #1711 at roughly 21:00Z. Nothing in those PRs touches the frontend.
The more serious half: one failing step disables the Go and IaC scanners
.github/workflows/ci.yml:317-321 runs npm audit as step 5 of the Security Scanning job. When it exits non-zero, every later scanner in the same job is skipped:
4. Run govulncheck CVE scanner (all modules) -> success
5. Run npm audit (frontend) -> FAILURE
6. Run gosec Security Scanner -> skipped
7. Upload gosec results to GitHub Security -> failure (no gosec-results.sarif)
8. Run Trivy vulnerability scanner (fs) -> skipped
9. Upload Trivy results -> skipped
10. Run Trivy IaC misconfiguration scanner -> skipped
11. Upload Trivy IaC results -> failure (no trivy-config-results.sarif)
So a frontend JavaScript advisory silently turns off Go SAST and Terraform IaC misconfiguration scanning for the whole repo. The two failure entries at steps 7 and 11 are missing-SARIF artefacts, which is a misleading symptom: the annotations read Path does not exist: gosec-results.sarif, pointing at the upload rather than the cause.
This matters beyond the current advisories. Any future frontend advisory, or any transient npm registry error, disables the security scanners that cover the money-path Go code and the IAM/Terraform definitions, while presenting as a single red check that a reader is likely to attribute to whatever they were touching.
Suggested fix
Two separable changes; the second is the one that keeps mattering after these advisories are patched.
- Patch the advisories.
npm audit fix in frontend/, restricted to the lockfile if possible so no direct dependency ranges move. Confirm npm audit --audit-level=high exits 0 and the frontend build and tests still pass.
- Decouple the scanners. The Go, IaC and JavaScript scanners should not be able to disable one another. Either split them into separate jobs, or ensure each scanner step runs regardless of its predecessors' outcome while still failing the job overall. Do not suppress the npm failure to make the job green: the goal is that a real npm finding is still reported, and gosec and Trivy still run.
Do not gate this behind an only-new-issues-style filter or otherwise mask the debt. Fix the advisories and the coupling.
Found while diagnosing a Security Scanning failure on #1711, which turned out to be unrelated to that PR's changes.
Two newly published high-severity npm advisories now fail
npm audit --audit-level=highinfrontend/, which reddens Security Scanning on every PR and onmain. Reproduced againstorigin/mainat02702a108:Both are transitive dependencies and both report
fix available via npm audit fix.This is time-dependent, not caused by any PR.
npm auditqueries the live advisory database, so the same commit passes or fails depending on when CI runs. Security Scanning passed on #1657 at16:39:46Z, #1658 at16:45:57Zand #1710 at17:07:11Z, then failed on #1711 at roughly21:00Z. Nothing in those PRs touches the frontend.The more serious half: one failing step disables the Go and IaC scanners
.github/workflows/ci.yml:317-321runsnpm auditas step 5 of theSecurity Scanningjob. When it exits non-zero, every later scanner in the same job is skipped:So a frontend JavaScript advisory silently turns off Go SAST and Terraform IaC misconfiguration scanning for the whole repo. The two
failureentries at steps 7 and 11 are missing-SARIF artefacts, which is a misleading symptom: the annotations readPath does not exist: gosec-results.sarif, pointing at the upload rather than the cause.This matters beyond the current advisories. Any future frontend advisory, or any transient npm registry error, disables the security scanners that cover the money-path Go code and the IAM/Terraform definitions, while presenting as a single red check that a reader is likely to attribute to whatever they were touching.
Suggested fix
Two separable changes; the second is the one that keeps mattering after these advisories are patched.
npm audit fixinfrontend/, restricted to the lockfile if possible so no direct dependency ranges move. Confirmnpm audit --audit-level=highexits 0 and the frontend build and tests still pass.Do not gate this behind an
only-new-issues-style filter or otherwise mask the debt. Fix the advisories and the coupling.Found while diagnosing a Security Scanning failure on #1711, which turned out to be unrelated to that PR's changes.