Skip to content

Commit 3f8fb67

Browse files
authored
ci: default audit-dependencies script to high severity (#13244)
Default the audit-dependencies workflow to use high severity by default.
1 parent 412bf4f commit 3f8fb67

File tree

2 files changed

+5
-4
lines changed

2 files changed

+5
-4
lines changed

.github/workflows/audit-dependencies.sh

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,15 @@
11
#!/bin/bash
22

3-
severity=${1:-"critical"}
4-
audit_json=$(pnpm audit --prod --json)
3+
severity=${1:-"high"}
54
output_file="audit_output.json"
65

76
echo "Auditing for ${severity} vulnerabilities..."
87

8+
audit_json=$(pnpm audit --prod --json)
9+
910
echo "${audit_json}" | jq --arg severity "${severity}" '
1011
.advisories | to_entries |
11-
map(select(.value.patched_versions != "<0.0.0" and .value.severity == $severity) |
12+
map(select(.value.patched_versions != "<0.0.0" and (.value.severity == $severity or ($severity == "high" and .value.severity == "critical"))) |
1213
{
1314
package: .value.module_name,
1415
vulnerable: .value.vulnerable_versions,

.github/workflows/audit-dependencies.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ on:
99
audit-level:
1010
description: The level of audit to run (low, moderate, high, critical)
1111
required: false
12-
default: critical
12+
default: high
1313
debug:
1414
description: Enable debug logging
1515
required: false

0 commit comments

Comments
 (0)