diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 8d28979..e9c8449 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -76,6 +76,17 @@ jobs: # lockfile update would install fine here and differ from every other # machine — drift that only surfaces later, somewhere else. - run: pnpm install --frozen-lockfile + # pnpm-workspace.yaml's auditConfig.ignoreGhsas sets assessed advisories + # aside by ID, each with a recheck date. This step fails once the + # earliest date passes, so an exception cannot outlive its reasoning: + # remove the entry if a fix installs, or reassess and move the date. + - name: Advisories set aside are still within their recheck date + run: | + recheck=2026-11-03 # GHSA-ch52-4w7c-c8xp (http-cache-semantics) + if [[ "$(date -u +%F)" > "$recheck" ]]; then + echo "::error::GHSA-ch52-4w7c-c8xp was set aside until $recheck: recheck it (pnpm-workspace.yaml)" + exit 1 + fi - run: pnpm audit --audit-level=high build: diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index f33e57b..3caa0f3 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -5,3 +5,16 @@ packages: - nyuchi-docs-mcp - nyuchi-docs-skills - nyuchi-docs-mcp-worker + +# Advisories set aside in `pnpm audit`, by ID only. Each has its reason, the +# date it was added and a recheck date; .github/workflows/build.yml fails the +# audit job once that date passes, so nothing stays here by default. +auditConfig: + ignoreGhsas: + # GHSA-ch52-4w7c-c8xp — http-cache-semantics <=4.2.0, no patched release. + # Added 2026-10-03, recheck by 2026-11-03. astro (via starlight in site + # and nyuchi-docs-search) uses it only in assets/build/remote.js, to cache + # remote images during `astro build`. The site ships as static assets + # behind src/worker/gate.ts, which does not import astro, so the + # vulnerable max-stale path never runs for a visitor. + - GHSA-ch52-4w7c-c8xp