-
Notifications
You must be signed in to change notification settings - Fork 19
Open
Labels
enhancementNew feature or requestNew feature or requestrisk-radarRisk Radar mitigation measuresRisk Radar mitigation measurestier-1Tier 1 - Automated GatesTier 1 - Automated Gates
Description
Context
As identified in the Risk Radar Assessment, both modules (scripts and website) are Tier 2 and require Tier 1 automated gates.
Measure: Dependency Check
Type: Deterministic
Status: ❌ Missing
Required for: Tier 1 — Automated Gates
What to implement
-
Add
npm auditstep to.github/workflows/test.yml:- name: Run dependency audit working-directory: ./website run: npm audit --audit-level=moderate
-
Add audit step for scripts module as well
-
Configure audit level (moderate = fail on moderate+ vulnerabilities)
-
Optional: Add
npm audit fixto automatically fix vulnerabilities
Reference
Acceptance Criteria
-
npm auditruns in CI for both modules - CI fails if moderate or higher vulnerabilities are found
- Audit results are visible in CI logs
- Dependencies are regularly checked for vulnerabilities
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestrisk-radarRisk Radar mitigation measuresRisk Radar mitigation measurestier-1Tier 1 - Automated GatesTier 1 - Automated Gates