From 0692224ab10ab64ef8c2e2c1245be8821a5c40e0 Mon Sep 17 00:00:00 2001 From: Derek Date: Tue, 29 Sep 2026 08:14:45 +1000 Subject: [PATCH] fix(ci): state the reason for the warn-level npm audit gate hyperi-ci now requires a reason when a security gate is relaxed below its default. The reason was already in a comment; it moves into the reason field. --- .hyperi-ci.yaml | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/.hyperi-ci.yaml b/.hyperi-ci.yaml index 650def0..8e53fee 100644 --- a/.hyperi-ci.yaml +++ b/.hyperi-ci.yaml @@ -14,18 +14,17 @@ quality: - windows typescript: - # Warn rather than block. Both open advisories are in `tar` and - # `brace-expansion`, bundled inside the `npm` that @semantic-release/npm - # vendors -- npm cannot patch a bundled dependency, and the only offered - # remedy downgrades semantic-release. - # - # The release workflow installs semantic-release globally at @latest and - # never installs from this tree, so nothing CI runs is built from the - # audited dependency graph. - # # Kept visible rather than disabled, and `hyperi-ci check --strict` # promotes it back to blocking. - audit: warn + audit: + mode: warn + reason: >- + Both open advisories are in tar and brace-expansion, bundled inside the + npm that @semantic-release/npm vendors. npm cannot patch a bundled + dependency, and the only offered remedy downgrades semantic-release. + The release workflow installs semantic-release globally at @latest and + never installs from this tree, so nothing CI runs is built from the + audited dependency graph. build: # Nothing to build. The TypeScript handler runs `npm run build`, and there is