Skip to content

CI: Security Audit failing on the default branch (npm audit) #1162

Description

@itsmiso-ai

Security Audit has failed twice in a row on the default branch, for the same reason.

A single red run is not filed — this one repeated, so it is a condition rather than a transient.

npm audit fix --force

Run `npm audit` for details.
npm warn install-scripts 1 package has install scripts not yet covered by allowScripts:
npm warn install-scripts   @prisma/engines@7.10.0 (postinstall: node scripts/postinstall.js)
npm warn install-scripts
npm warn install-scripts Run `npm install-scripts ls` to review, or `npm install-scripts approve <pkg>` to allow.
##[group]Run npm run audit
�[36;1mnpm run audit�[0m
shell: /usr/bin/bash -e {0}
##[endgroup]

> dispatch@0.5.67 audit
> npm audit --omit=dev --audit-level=high --fetch-retries=5 --fetch-timeout=120000 --fetch-retry-mintimeout=20000 --fetch-retry-maxtimeout=120000

# npm audit report

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install eslint-config-next@14.2.35, which is a breaking change
node_modules/braces
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/fast-glob
      @next/eslint-plugin-next  >=14.3.0-canary.0
      Depends on vulnerable versions of fast-glob
      node_modules/@next/eslint-plugin-next
        eslint-config-next  >=14.3.0-canary.0
        Depends on vulnerable versions of @next/eslint-plugin-next
        node_modules/eslint-config-next

5 high severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force
##[error]Process completed with exit code 1.
Post job cleanup.
##[start-action display=Setup Node;id=__b703c60a-07d7-4b19-bb0c-da807f48d25e.__actions_setup-node]
##[end-action id=__b703c60a-07d7-4b19-bb0c-da807f48d25e.__actions_setup-node;outcome=skipped;conclusion=skipped;duration_ms=0]
Post job cleanup.
[command]/usr/bin/git version
git version 2.55.0
Temporarily overriding HOME='/home/runner/work/_temp/23b93114-c400-4e26-bd58-e589b16dbc92' before making global git config changes
Adding repository directory to the temporary git global config as a safe directory
[command]/usr/bin/git config --global --add safe.directory /home/runner/work/dispatch/dispatch
Removing SSH command configuration
[command]/usr/bin/git config --local --name-only --get-regexp core\.sshCommand
[command]/usr/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'core\.sshCommand' && git config --local --unset-all 'core.sshCommand' || :"
Removing HTTP extra header
[command]/usr/bin/git config --local --name-only --get-regexp http\.https\:\/\/github\.com\/\.extraheader

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions