File tree Expand file tree Collapse file tree 3 files changed +22
-3
lines changed Expand file tree Collapse file tree 3 files changed +22
-3
lines changed Original file line number Diff line number Diff line change
1
+ {
2
+ "moderate" : true ,
3
+ "high" : true ,
4
+ "critical" : true ,
5
+ "advisories" : [" 1096727" ],
6
+ "allowlist" : {
7
+ "1096727" : {
8
+ "reason" : " request package - SSRF vulnerability but no patch available. Used by octonode dependency." ,
9
+ "expiry" : " 2025-12-31"
10
+ }
11
+ },
12
+ "report-type" : " full" ,
13
+ "output-format" : " text" ,
14
+ "skip-dev" : false
15
+ }
Original file line number Diff line number Diff line change 60
60
run : yarn install --frozen-lockfile
61
61
62
62
- name : Run dependency security audit
63
- run : yarn audit --groups dependencies --level moderate
63
+ run : yarn security: audit
64
64
65
65
- name : Run detect-secrets
66
66
run : |
@@ -90,10 +90,10 @@ jobs:
90
90
run : yarn install --frozen-lockfile
91
91
92
92
- name : Run linting for ${{ matrix.app }}
93
- run : turbo run lint --filter=${{ matrix.app }}
93
+ run : yarn lint --filter=${{ matrix.app }} --fix
94
94
95
95
- name : Run tests for ${{ matrix.app }}
96
- run : turbo run test --filter=${{ matrix.app }} -- --coverage --watchAll=false
96
+ run : yarn test --filter=${{ matrix.app }} -- --coverage --watchAll=false
97
97
98
98
- name : Upload coverage reports to Codecov
99
99
uses : codecov/codecov-action@v4
Original file line number Diff line number Diff line change 37
37
"secrets:check" : " scripts/detect-secrets.sh" ,
38
38
"secrets:check:staged" : " scripts/detect-secrets-staged.sh" ,
39
39
"secrets:setup" : " detect-secrets scan --update .secrets.baseline" ,
40
+ "security:audit" : " audit-ci --config .audit-ci.json" ,
41
+ "security:audit-better" : " better-npm-audit audit --level moderate" ,
40
42
"seed:update" : " turbo run seed:update --filter=api" ,
41
43
"setup" : " [ -d \" $(git rev-parse --show-toplevel)/apps/api\" ] && cd \" $(git rev-parse --show-toplevel)/apps/api\" && dotenv -e ./dev.env -- npx prisma migrate dev && npx prisma generate; cd $(git rev-parse --show-toplevel)" ,
42
44
"setup:no-git" : " cd ./apps/api && dotenv -e ./dev.env -- npx prisma migrate dev && npx prisma generate; cd ../../" ,
96
98
"zod" : " ^3.23.5"
97
99
},
98
100
"devDependencies" : {
101
+ "audit-ci" : " ^7.1.0" ,
102
+ "better-npm-audit" : " ^3.8.0" ,
99
103
"detect-secrets" : " ^1.0.6" ,
100
104
"dotenv-cli" : " ^8.0.0" ,
101
105
"prettier" : " ^3.5.3" ,
You can’t perform that action at this time.
0 commit comments