Repository navigation
fix(ci): clear stale audit-gate entries and bump fixed advisories - #1942
Conversation
npm audit fix cleared brace-expansion (5.0.7 -> 5.0.9, GHSA-mh99-v99m-4gvg) and valibot (1.2.0 -> 1.4.2, GHSA-5qjj-4xww-7phc). The @discordjs/opus -> node-pre-gyp -> rimraf -> glob -> minimatch chain is no longer reported as high/critical in production deps, so the gate's own anti-rot check failed on its stale ACCEPTED entries. Delete them as the gate instructs. react-router/react-router-dom remain accepted pending the v8 migration (#1878).
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
📝 WalkthroughWalkthroughThe production audit gate removes accepted entries for ChangesAudit gate updates
Estimated code review effort: 2 (Simple) | ~5 minutes Possibly related issues
Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Failed to generate code suggestions for PR |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
This pull request updates dependencies in package-lock.json, including version bumps for several @prisma/* packages (from 7.9.0 to 7.9.1) and related transitive dependencies like find-my-way, valibot, and brace-expansion. It also removes a nested undici entry and adjusts metadata on various platform-specific optional packages (adding dev: true flags and removing libc fields). The changed symbols reference an audit gate script, suggesting the lockfile changes may relate to resolving flagged advisories or vulnerabilities, though the truncated diff doesn't show those script contents directly.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 8 functions depend on the 8 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 8 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 8 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
No issues found across 2 files
Auto-approved: Removes stale audit-gate entries and applies minor dependency upgrades (brace-expansion, valibot, Prisma) via npm audit fix. The change is bounded, non-breaking, and fixes CI failure.
Re-trigger cubic
|
🤖 I have created a release *beep* *boop* --- <details><summary>2.39.2</summary> ## [2.39.2](v2.39.1...v2.39.2) (2026-08-10) ### Bug Fixes * **bot:** guard voice/session mutations with stop/suppress flags ([#1998](#1998)) ([23eaba2](23eaba2)) * **ci:** clear stale audit-gate entries and bump fixed advisories ([#1942](#1942)) ([adf710b](adf710b)) * **ci:** clear stale audit-gate entries and bump fixed advisories ([#1960](#1960)) ([2c17c99](2c17c99)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).



Why
Security gate fails on every PR (e.g. #1941):
scripts/audit-gate.mjsexits 1 because its own anti-rot check found 4 ACCEPTED entries that are no longer reported (@discordjs/node-pre-gyp,rimraf,glob,minimatch) — and behind that,brace-expansionwas blocking on a re-issued advisory id.What
npm audit fix(non-breaking):brace-expansion5.0.7 → 5.0.9 (GHSA-mh99-v99m-4gvg),valibot1.2.0 → 1.4.2 (GHSA-5qjj-4xww-7phc); nested vulnerable brace-expansion copies deduped.scripts/audit-gate.mjs(the @discordjs/opus → node-pre-gyp chain is now only reported as moderate, below the gate's high/critical bar).react-router/react-router-domstay accepted pending the v8 migration (security(frontend): migrate to react-router v8 to clear GHSA-qwww-vcr4-c8h2 #1878) — untouched.Verification
node scripts/audit-gate.mjs→ exit 0: "No unaccepted high/critical findings in production dependencies." Production audit now reports only the accepted react-router pair as high.Relates #1879 (dev toolchain advisories — partial; this clears the production-visible ones).
Summary by cubic
Fixes the CI security audit gate by removing stale ACCEPTED entries and applying non‑breaking
npm audit fixupdates. The gate now passes; only the acceptedreact-routerpair remains high until the v8 migration.Bug Fixes
scripts/audit-gate.mjsfor the@discordjs/node-pre-gyp→rimraf→glob→minimatch→brace-expansionchain (no longer high/critical in prod).react-router/react-router-domremain accepted pending v8 migration (security(frontend): migrate to react-router v8 to clear GHSA-qwww-vcr4-c8h2 #1878).Dependencies
brace-expansion5.0.7 → 5.0.9 (GHSA-mh99-v99m-4gvg).valibot1.2.0 → 1.4.2 (GHSA-5qjj-4xww-7phc).Written for commit 169ea64. Summary will update on new commits.
Summary by CodeRabbit