Skip to content

chore(ci): dev-only transitive npm advisories block the entire merge queue (2 emergencies in 3 days) #165

Description

@cristim

npm audit --audit-level=high gates the Security Scanning job, which gates CI Success, which is now a required check on main. So any new npm advisory — anywhere in the dependency tree — halts every open PR until someone lands an emergency lockfile bump.

This has now happened twice in three days.

date advisories dependency path production exposure
LeanerCloud/cloud-commitments-cli#1716 brace-expansion GHSA-rgw5-rvv9-x895, fast-uri GHSA-7p8r-x3mc-p8w7 transitive none — dev-only
LeanerCloud/cloud-commitments-cli#1729 js-yaml GHSA-5p4m-2wfm-xmqj, nanoid GHSA-2v37-7h3g-55p8 eslint; ts-jest -> @jest/transform -> babel-plugin-istanbul -> @istanbuljs/load-nyc-config; css-loader -> postcss none — dev-only

Every advisory so far has been on a dev-only transitive dependency. Not one has been a direct dependency, and not one has been reachable from shipped production code. Both times the fix resolved within the parents' existing semver ranges, so package.json never moved.

The cost each time is a same-day emergency PR that blocks six or more unrelated PRs, none of which touch JavaScript.

What this is not asking for

npm audit --omit=dev is prohibited in this repo and is not being proposed. Suppressing a whole class of findings to get green is masking CI debt, which is a standing owner directive against exactly this shortcut. The advisories are real and should still be surfaced and fixed.

The actual question

Should a dev-only transitive advisory block every merge in the repo, or should it be surfaced without gating?

Some directions worth weighing, none of them suppression:

  • Split the signal. Keep a blocking audit over production dependencies, and run the full-tree audit as its own non-blocking job that still fails visibly and still gets fixed — just without holding unrelated PRs hostage. This reports strictly more than today; it only changes what blocks.
  • Scheduled audit + auto-PR. A daily job that opens the lockfile bump automatically, so the fix is already in flight before anyone notices the queue is red. Removes the emergency without removing the check.
  • Accept the cadence. If dev-toolchain advisories genuinely warrant blocking merges, that is a legitimate call — but it should be a deliberate one, with the ~2-per-3-days rate understood, rather than the accidental consequence of Security Scanning being a required check.

Related

Data gathered while fixing LeanerCloud/cloud-commitments-cli#1729.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions