Skip to content

chore(ci): align electron audit gate to root advisory policy - #4275

Merged
diegosouzapw merged 1 commit into
release/v3.8.30from
chore/align-electron-audit-gate
Jun 19, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.30from
chore/align-electron-audit-gate

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Summary

The audit:electron step blocked at --audit-level=moderate, while the root audit:deps gate blocks only on critical and treats high as a non-blocking ::warning::. That asymmetry let a transitive HIGH advisory in build-time tooling fail the whole Lint job on release/v3.8.30 — even on a no-op (version-bump-only) commit — with no clean fix available.

The blocking advisory

undici (HIGH) pulled transitively by node-gyp / electron-builder / @electron/rebuild:

  • GHSA-vmh5-mc38-953g — TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
  • GHSA-pr7r-676h-xcf6 — cross-user information disclosure via shared cache whitespace bypass

This is build-time tooling, not runtime. There is no clean non-breaking fix: the root undici is already at the latest published 8.x, and electron's copies are transitive multi-version. This is the same advisory v3.8.29 was merged over.

Change

One line — mirror the root policy in audit:electron: block on critical, surface high as a non-blocking warning. Criticals still block; moderate/high transitive advisories in build tooling now warn instead of failing the gate.

-    "audit:electron": "npm --prefix electron audit --audit-level=moderate",
+    "audit:electron": "npm --prefix electron audit --audit-level=critical && (npm --prefix electron audit --audit-level=high || echo '::warning::electron high-severity advisories present (non-blocking)')",

Validation (RED→GREEN — CI-only, no product code; Rule #8/#18 N/A)

  • before: npm run audit:deps → exit 1
  • after: npm run audit:deps → exit 0 (emits ::warning::electron high-severity advisories present (non-blocking))

The `audit:electron` step blocked at `--audit-level=moderate`, while the
root `audit:deps` gate blocks only on `critical` and treats `high` as a
non-blocking `::warning::`. That asymmetry let a transitive HIGH advisory
in build-time tooling (undici via node-gyp/electron-builder/@electron/rebuild
— GHSA-vmh5-mc38-953g, GHSA-pr7r-676h-xcf6) fail the whole "Lint" job on
release/v3.8.30, even on a no-op commit, with no clean fix available
(root undici is already at the latest 8.x; electron's copies are transitive
in build tooling, not runtime).

Mirror the root policy in audit:electron: block on `critical`, surface `high`
as a non-blocking warning. Moderate/high transitive advisories in build
tooling now warn instead of blocking the gate; criticals still block.

Validation (RED->GREEN, no product code touched — Rule #8/#18 N/A for CI-only):
  before: `npm run audit:deps` -> exit 1
  after:  `npm run audit:deps` -> exit 0 (emits the high-advisory warning)
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@diegosouzapw
diegosouzapw merged commit 8aa9d63 into release/v3.8.30 Jun 19, 2026
4 checks passed

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the audit:electron script in package.json to only fail on critical-severity vulnerabilities while displaying a non-blocking warning for high-severity vulnerabilities, aligning its behavior with the audit:deps script. No review comments were provided, and there is no additional feedback to address.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@diegosouzapw diegosouzapw mentioned this pull request Jun 20, 2026
@diegosouzapw
diegosouzapw deleted the chore/align-electron-audit-gate branch June 21, 2026 12:33
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…uzapw#4275)

Align electron audit gate to root policy (critical blocks, high warns). Un-blocks the Lint job on release/v3.8.30.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant