Repository navigation
CI: Security Audit failing on the default branch (npm audit) #1166
Description
Activity
The braces advisory (GHSA-vfj7-8cjw-p6xm) enters through eslint-config-next -> @next/eslint-plugin-next -> fast-glob -> micromatch -> braces. The fix follows the repo's established pattern: add a braces override to package.json, regenerate the lockfile, guard it in package-overrides.test.ts, and update SECURITY-ACCEPTED-RISKS.md. The npm warn install-scripts lines for @prisma/engines in the CI log are unrelated warnings and not the failure cause.
Fix proposed in #1172. One deviation from the grooming suggestion above, verified before deviating: a braces override cannot work here. The advisory's vulnerable range is <=3.0.3 and the latest published braces is 3.0.3 (checked against the registry: dist-tags.latest = 3.0.3, advisory id 1240992) — there is no patched version to pin, so any override keeps the vulnerability report identical. npm audit fix --force itself only proposes a breaking eslint-config-next downgrade (14.2.35), which resolves through the same fast-glob -> micromatch chain.
Instead, #1172 fixes the gate's actual latent bug: .npmrc include=dev (intentional, #428) overrides --omit in npm's config, so npm audit --omit=dev has been auditing the dev tree all along. The audit script now passes an explicit --include=prod, restoring the intended production+optional scope (empirically verified: prod- and optional-installed vulnerable packages are still reported; dev-only chains are not), plus a regression test and a non-blocking dev-inclusive audit step for visibility. The @prisma/engines install-scripts warning was treated as unrelated, as the grooming note says.
Security Audithas failed twice in a row on the default branch, for the same reason.b0863de9)34f01623)npm auditA single red run is not filed — this one repeated, so it is a condition rather than a transient.