Skip to content

Pull requests are gated on the advisories they add; the inventory runs on main and daily - #849

Merged
irparent merged 1 commit into
mainfrom
ci/advisories-by-pr
Oct 5, 2026
Merged

irparent merged 1 commit into
mainfrom
ci/advisories-by-pr

Conversation

@irparent

@irparent irparent commented Oct 5, 2026

Copy link
Copy Markdown
Member

What changes

security-exposure ran the full advisory inventory (npm audit against SECURITY-EXPOSURE.md) on every pull request. So each newly published advisory turned every open PR red at once, about changes none of them made, and each needed the same triage row or a rebase. That happened three times on 10-02 and 10-03.

Where Before Now
Pull request the whole inventory GitHub's dependency review: fails only on a dependency the PR's own changes bring in with an advisory of moderate or above. The GHSA ids SECURITY-EXPOSURE.md already triages are allowed, so adding a triage row inside the PR still clears it
Push to main the whole inventory the same
Daily nothing advisory-inventory.yml runs the inventory, because an advisory can be published with nothing merged

The required check keeps its name, so branch protection is unchanged. The gate's own rule, that a blocking gate must be satisfiable inside the change it blocks, holds on both paths.

Tests

  • actionlint (the pinned image CI uses) passes on every workflow; actions/dependency-review-action is pinned to the v5.0.0 commit, whose inputs were read from its action.yml at that commit.
  • preflight-mirrors-ci, required-checks-documented, workflows-build-order and the tests that read the exposure files pass.
  • npm run preflight passed on this commit.

🤖 Generated with Claude Code

…runs on main and daily

security-exposure ran the full advisory inventory (npm audit against
SECURITY-EXPOSURE.md) on every pull request, so each newly published
advisory turned every open PR red at once, about changes none of them
made, and each needed the same triage row or a rebase (three times on
10-02 and 10-03).

- On a pull request the job now runs GitHub's dependency review: it fails
  only on a dependency the PR's own changes bring in with an advisory of
  moderate or above, and allows the GHSA ids SECURITY-EXPOSURE.md already
  triages, so the triage-row exit still works inside the PR.
- On main it runs the inventory, as before, and advisory-inventory.yml
  runs it daily, because an advisory can be published with nothing merged.

The required check keeps its name, so branch protection is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
website Ignored Ignored Oct 5, 2026 10:39pm UTC

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Iris gate — 1 of 2 tripped --fail-on detector_veto

iris-eval ingest: 3 stored, 1 tripped --fail-on detector_veto (2 of 3 evaluated in dataset "release-gate")

Trace Verdict Basis Rules, classes or missing inputs Evidence
475421ca3faae08b16534183bc0fce2e failed detector_veto + risk_over_loss no_pii, pii_leak, credential_leak no_pii: AWS Access Key (output 45–65)
Verdict basis Traces
detector_veto 2
clean 1

Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Iris gate — 1 stored, nothing tripped --fail-on any

iris-eval ingest: 1 stored, 0 tripped --fail-on any

Verdict basis Traces
clean 1

Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean

@irparent
irparent merged commit 20c304e into main Oct 5, 2026
73 checks passed
@irparent
irparent deleted the ci/advisories-by-pr branch October 5, 2026 23:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant