Skip to content

CI: Security Audit failing on the default branch (npm audit) #1166

Description

@itsmiso-ai

Security Audit has failed twice in a row on the default branch, for the same reason.

A single red run is not filed — this one repeated, so it is a condition rather than a transient.

npm audit fix --force

Run `npm audit` for details.
npm warn install-scripts 1 package has install scripts not yet covered by allowScripts:
npm warn install-scripts   @prisma/engines@7.10.0 (postinstall: node scripts/postinstall.js)
npm warn install-scripts
npm warn install-scripts Run `npm install-scripts ls` to review, or `npm install-scripts approve <pkg>` to allow.
##[group]Run npm run audit
�[36;1mnpm run audit�[0m
shell: /usr/bin/bash -e {0}
##[endgroup]

> dispatch@0.5.67 audit
> npm audit --omit=dev --audit-level=high --fetch-retries=5 --fetch-timeout=120000 --fetch-retry-mintimeout=20000 --fetch-retry-maxtimeout=120000

# npm audit report

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install eslint-config-next@14.2.35, which is a breaking change
node_modules/braces
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/fast-glob
      @next/eslint-plugin-next  >=14.3.0-canary.0
      Depends on vulnerable versions of fast-glob
      node_modules/@next/eslint-plugin-next
        eslint-config-next  >=14.3.0-canary.0
        Depends on vulnerable versions of @next/eslint-plugin-next
        node_modules/eslint-config-next

5 high severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force
##[error]Process completed with exit code 1.
Post job cleanup.
##[start-action display=Setup Node;id=__4c8259ae-2d21-4e3b-a345-e09d68506a49.__actions_setup-node]
##[end-action id=__4c8259ae-2d21-4e3b-a345-e09d68506a49.__actions_setup-node;outcome=skipped;conclusion=skipped;duration_ms=0]
Post job cleanup.
[command]/usr/bin/git version
git version 2.55.0
Temporarily overriding HOME='/home/runner/work/_temp/661be57f-ff1b-4164-8e4f-9e16900e0ea3' before making global git config changes
Adding repository directory to the temporary git global config as a safe directory
[command]/usr/bin/git config --global --add safe.directory /home/runner/work/dispatch/dispatch
Removing SSH command configuration
[command]/usr/bin/git config --local --name-only --get-regexp core\.sshCommand
[command]/usr/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'core\.sshCommand' && git config --local --unset-all 'core.sshCommand' || :"
Removing HTTP extra header
[command]/usr/bin/git config --local --name-only --get-regexp http\.https\:\/\/github\.com\/\.extraheader

Activity

itsmiso-ai commented on Oct 3, 2026

@itsmiso-ai
ContributorAuthor

The braces advisory (GHSA-vfj7-8cjw-p6xm) enters through eslint-config-next -> @next/eslint-plugin-next -> fast-glob -> micromatch -> braces. The fix follows the repo's established pattern: add a braces override to package.json, regenerate the lockfile, guard it in package-overrides.test.ts, and update SECURITY-ACCEPTED-RISKS.md. The npm warn install-scripts lines for @prisma/engines in the CI log are unrelated warnings and not the failure cause.

itsmiso-ai commented on Oct 3, 2026

@itsmiso-ai
ContributorAuthor

Fix proposed in #1172. One deviation from the grooming suggestion above, verified before deviating: a braces override cannot work here. The advisory's vulnerable range is <=3.0.3 and the latest published braces is 3.0.3 (checked against the registry: dist-tags.latest = 3.0.3, advisory id 1240992) — there is no patched version to pin, so any override keeps the vulnerability report identical. npm audit fix --force itself only proposes a breaking eslint-config-next downgrade (14.2.35), which resolves through the same fast-glob -> micromatch chain.

Instead, #1172 fixes the gate's actual latent bug: .npmrc include=dev (intentional, #428) overrides --omit in npm's config, so npm audit --omit=dev has been auditing the dev tree all along. The audit script now passes an explicit --include=prod, restoring the intended production+optional scope (empirically verified: prod- and optional-installed vulnerable packages are still reported; dev-only chains are not), plus a regression test and a non-blocking dev-inclusive audit step for visibility. The @prisma/engines install-scripts warning was treated as unrelated, as the grooming note says.

added
status/in-reviewPull request or human review is in progress.
and removed on Oct 3, 2026
added and removed
status/in-reviewPull request or human review is in progress.
on Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions