Skip to content

fix(ci): clear stale audit-gate entries and bump fixed advisories - #1942

Merged
LucasSantana-Dev merged 1 commit into
mainfrom
fix/audit-gate-stale-entries
Aug 3, 2026
Merged

LucasSantana-Dev merged 1 commit into
mainfrom
fix/audit-gate-stale-entries

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Aug 3, 2026 •

Copy link
Copy Markdown
Owner

Why

Security gate fails on every PR (e.g. #1941): scripts/audit-gate.mjs exits 1 because its own anti-rot check found 4 ACCEPTED entries that are no longer reported (@discordjs/node-pre-gyp, rimraf, glob, minimatch) — and behind that, brace-expansion was blocking on a re-issued advisory id.

What

Verification

node scripts/audit-gate.mjs → exit 0: "No unaccepted high/critical findings in production dependencies." Production audit now reports only the accepted react-router pair as high.

Relates #1879 (dev toolchain advisories — partial; this clears the production-visible ones).


Summary by cubic

Fixes the CI security audit gate by removing stale ACCEPTED entries and applying non‑breaking npm audit fix updates. The gate now passes; only the accepted react-router pair remains high until the v8 migration.

Written for commit 169ea64. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Removed several accepted production-audit entries and their associated advisory rationale and version pinning.

npm audit fix cleared brace-expansion (5.0.7 -> 5.0.9, GHSA-mh99-v99m-4gvg)
and valibot (1.2.0 -> 1.4.2, GHSA-5qjj-4xww-7phc). The @discordjs/opus ->
node-pre-gyp -> rimraf -> glob -> minimatch chain is no longer reported as
high/critical in production deps, so the gate's own anti-rot check failed on
its stale ACCEPTED entries. Delete them as the gate instructs.

react-router/react-router-dom remain accepted pending the v8 migration
(#1878).
@github-actions github-actions Bot added dependencies Pull requests that update a dependency file infra size/l labels Aug 3, 2026
@coderabbitai

coderabbitai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 0da04fb7-cf5d-4996-b712-6da2f6d04e42

📥 Commits

Reviewing files that changed from the base of the PR and between fdca34a and 169ea64.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • scripts/audit-gate.mjs
💤 Files with no reviewable changes (1)
  • scripts/audit-gate.mjs

📝 Walkthrough

Walkthrough

The production audit gate removes accepted entries for @discordjs/node-pre-gyp, rimraf, glob, minimatch, and brace-expansion.

Changes

Audit gate updates

Layer / File(s) Summary
Remove accepted vulnerability entries
scripts/audit-gate.mjs
Removes accepted production-audit entries and related advisory pinning for the dependency chain.

Estimated code review effort: 2 (Simple) | ~5 minutes

Possibly related issues

Possibly related PRs

Suggested reviewers: cubic-dev-ai

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the CI audit-gate cleanup and advisory updates covered by the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/audit-gate-stale-entries

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm effect is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.json → npm/effect@3.22.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/effect@3.22.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This pull request updates dependencies in package-lock.json, including version bumps for several @prisma/* packages (from 7.9.0 to 7.9.1) and related transitive dependencies like find-my-way, valibot, and brace-expansion. It also removes a nested undici entry and adjusts metadata on various platform-specific optional packages (adding dev: true flags and removing libc fields). The changed symbols reference an audit gate script, suggesting the lockfile changes may relate to resolving flagged advisories or vulnerabilities, though the truncated diff doesn't show those script contents directly.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 8 functions depend on the 8 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 8 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 8 function(s) in the blast radius were not formally verified this run

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Auto-approved: Removes stale audit-gate entries and applies minor dependency upgrades (brace-expansion, valibot, Prisma) via npm audit fix. The change is bounded, non-breaking, and fixes CI failure.

Re-trigger cubic

@sonarqubecloud

sonarqubecloud Bot commented Aug 3, 2026

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit adf710b into main Aug 3, 2026
47 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/audit-gate-stale-entries branch August 3, 2026 10:40
LucasSantana-Dev added a commit that referenced this pull request Aug 11, 2026
🤖 I have created a release *beep* *boop*
---


<details><summary>2.39.2</summary>

##
[2.39.2](v2.39.1...v2.39.2)
(2026-08-10)


### Bug Fixes

* **bot:** guard voice/session mutations with stop/suppress flags
([#1998](#1998))
([23eaba2](23eaba2))
* **ci:** clear stale audit-gate entries and bump fixed advisories
([#1942](#1942))
([adf710b](adf710b))
* **ci:** clear stale audit-gate entries and bump fixed advisories
([#1960](#1960))
([2c17c99](2c17c99))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
This was referenced Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file infra size/l

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant