@@ -89,42 +89,53 @@ const rootAudit = npmAudit(ROOT)
8989assert . strictEqual ( rootAudit . metadata ?. vulnerabilities ?. total , 0 , 'root production dependency audit must remain clean' )
9090assert . deepStrictEqual ( advisoryIds ( rootAudit ) , policy . rootAllowedAdvisories )
9191
92- const websiteAudit = npmAudit ( WEBSITE )
9392const allowedAdvisories = policy . websiteExceptions . map ( item => item . advisoryId ) . sort ( )
94- assert . deepStrictEqual ( advisoryIds ( websiteAudit ) , allowedAdvisories , 'website advisory set changed; review before updating policy' )
95- const vulnerabilityPackages = Object . keys ( websiteAudit . vulnerabilities || { } ) . sort ( )
96- assert . deepStrictEqual (
97- vulnerabilityPackages ,
98- [ ...policy . websiteAllowedPackages ] . sort ( ) ,
99- 'website vulnerability dependency chain changed'
100- )
101-
10293const today = new Date ( ) . toISOString ( ) . slice ( 0 , 10 )
10394for ( const exception of policy . websiteExceptions ) {
10495 assert . ok ( today <= exception . expiresOn , `${ exception . advisoryId } exception expired on ${ exception . expiresOn } ` )
10596 assert . strictEqual ( exception . disposition , 'not-applicable-to-static-rspress-site' )
10697 assert . ok ( exception . replacementTrigger )
10798}
10899
109- for ( const [ packageName , minimum ] of Object . entries ( policy . minimumVersions ) ) {
110- const installed = installedVersion ( packageName )
111- assert . ok (
112- compareVersion ( installed , minimum ) >= 0 ,
113- `${ packageName } @${ installed } is below the security floor ${ minimum } `
100+ const websitePackage = path . join ( WEBSITE , 'package.json' )
101+ if ( fs . existsSync ( websitePackage ) ) {
102+ const websiteAudit = npmAudit ( WEBSITE )
103+ assert . deepStrictEqual ( advisoryIds ( websiteAudit ) , allowedAdvisories , 'website advisory set changed; review before updating policy' )
104+ const vulnerabilityPackages = Object . keys ( websiteAudit . vulnerabilities || { } ) . sort ( )
105+ assert . deepStrictEqual (
106+ vulnerabilityPackages ,
107+ [ ...policy . websiteAllowedPackages ] . sort ( ) ,
108+ 'website vulnerability dependency chain changed'
114109 )
115- }
116110
117- const sourceRecords = websiteRuntimeSources ( ) . map ( file => ( {
118- file,
119- content : fs . readFileSync ( file , 'utf8' )
120- } ) )
121- for ( const pattern of policy . forbiddenWebsiteRuntimePatterns ) {
122- const match = sourceRecords . find ( record => record . content . includes ( pattern ) )
123- assert . ok ( ! match , `website runtime source enables unsupported RSC surface ${ pattern } : ${ match ?. file } ` )
124- }
111+ for ( const [ packageName , minimum ] of Object . entries ( policy . minimumVersions ) ) {
112+ const installed = installedVersion ( packageName )
113+ assert . ok (
114+ compareVersion ( installed , minimum ) >= 0 ,
115+ `${ packageName } @${ installed } is below the security floor ${ minimum } `
116+ )
117+ }
125118
126- console . log (
127- `security audit passed root=0 websiteExceptions=${ allowedAdvisories . join ( ',' ) } ` +
128- `expires=${ policy . websiteExceptions [ 0 ] . expiresOn } rspress=${ installedVersion ( '@rspress/core' ) } ` +
129- `reactRouter=${ installedVersion ( 'react-router' ) } braceExpansion=${ installedVersion ( 'brace-expansion' ) } `
130- )
119+ const sourceRecords = websiteRuntimeSources ( ) . map ( file => ( {
120+ file,
121+ content : fs . readFileSync ( file , 'utf8' )
122+ } ) )
123+ for ( const pattern of policy . forbiddenWebsiteRuntimePatterns ) {
124+ const match = sourceRecords . find ( record => record . content . includes ( pattern ) )
125+ assert . ok ( ! match , `website runtime source enables unsupported RSC surface ${ pattern } : ${ match ?. file } ` )
126+ }
127+
128+ console . log (
129+ `security audit passed root=0 websiteExceptions=${ allowedAdvisories . join ( ',' ) } ` +
130+ `expires=${ policy . websiteExceptions [ 0 ] . expiresOn } rspress=${ installedVersion ( '@rspress/core' ) } ` +
131+ `reactRouter=${ installedVersion ( 'react-router' ) } braceExpansion=${ installedVersion ( 'brace-expansion' ) } `
132+ )
133+ } else {
134+ const websiteReadme = fs . readFileSync ( path . join ( WEBSITE , 'README.md' ) , 'utf8' )
135+ assert . match ( websiteReadme , / 不 进 入 公 开 G i t 默 认 跟 踪 / )
136+ assert . match ( websiteReadme , / w e b s i t e 视 为 o p t i o n a l / )
137+ console . log (
138+ `security audit passed root=0 website=optional-absent ` +
139+ `policyExceptions=${ allowedAdvisories . join ( ',' ) } expires=${ policy . websiteExceptions [ 0 ] . expiresOn } `
140+ )
141+ }
0 commit comments