chore(ci): align electron audit gate to root advisory policy - #4275
Conversation
The `audit:electron` step blocked at `--audit-level=moderate`, while the root `audit:deps` gate blocks only on `critical` and treats `high` as a non-blocking `::warning::`. That asymmetry let a transitive HIGH advisory in build-time tooling (undici via node-gyp/electron-builder/@electron/rebuild — GHSA-vmh5-mc38-953g, GHSA-pr7r-676h-xcf6) fail the whole "Lint" job on release/v3.8.30, even on a no-op commit, with no clean fix available (root undici is already at the latest 8.x; electron's copies are transitive in build tooling, not runtime). Mirror the root policy in audit:electron: block on `critical`, surface `high` as a non-blocking warning. Moderate/high transitive advisories in build tooling now warn instead of blocking the gate; criticals still block. Validation (RED->GREEN, no product code touched — Rule #8/#18 N/A for CI-only): before: `npm run audit:deps` -> exit 1 after: `npm run audit:deps` -> exit 0 (emits the high-advisory warning)
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Code Review
This pull request updates the audit:electron script in package.json to only fail on critical-severity vulnerabilities while displaying a non-blocking warning for high-severity vulnerabilities, aligning its behavior with the audit:deps script. No review comments were provided, and there is no additional feedback to address.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
…uzapw#4275) Align electron audit gate to root policy (critical blocks, high warns). Un-blocks the Lint job on release/v3.8.30.
Summary
The
audit:electronstep blocked at--audit-level=moderate, while the rootaudit:depsgate blocks only oncriticaland treatshighas a non-blocking::warning::. That asymmetry let a transitive HIGH advisory in build-time tooling fail the whole Lint job onrelease/v3.8.30— even on a no-op (version-bump-only) commit — with no clean fix available.The blocking advisory
undici(HIGH) pulled transitively bynode-gyp/electron-builder/@electron/rebuild:requestTlsin SOCKS5 ProxyAgentThis is build-time tooling, not runtime. There is no clean non-breaking fix: the root
undiciis already at the latest published 8.x, and electron's copies are transitive multi-version. This is the same advisory v3.8.29 was merged over.Change
One line — mirror the root policy in
audit:electron: block oncritical, surfacehighas a non-blocking warning. Criticals still block; moderate/high transitive advisories in build tooling now warn instead of failing the gate.Validation (RED→GREEN — CI-only, no product code; Rule #8/#18 N/A)
npm run audit:deps→ exit 1npm run audit:deps→ exit 0 (emits::warning::electron high-severity advisories present (non-blocking))