Skip to content

fix(secu): enforce dependency-analysis lockfile and blocklist checks - #73

Merged
sc979 merged 4 commits into
mainfrom
SECU-dependencyAnalysis-fixLockfileVersionCheck
Oct 1, 2026
Merged

sc979 merged 4 commits into
mainfrom
SECU-dependencyAnalysis-fixLockfileVersionCheck

Conversation

@sc979

@sc979 sc979 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Description

What are your needs or what are you planning to do in this PR?

Fixes: SECU-1239

Make the dependency-analysis reusable workflow actually enforce the checks it reports:

  • Outdated pnpm lockfile: compare_version ran in a $(...) subshell, so FORCE_FAIL was lost and an outdated lockfile never broke the run after the enforcement date. It now runs in the current shell. A lockfile without lockfileVersion is reported as outdated instead of aborting the step under -o pipefail.
  • Blocklist: a dependency matching the blocklist now always fails the build, regardless of the enforcement date.
  • Missing lockfile: the "A lockfile is required" case could never trigger (it sat inside the loop over found lockfiles). It now applies to package.json files that declare dependencies and are not covered by a pnpm-lock.yaml in a parent directory (workspace members), and follows the enforcement date.
  • Third-party code: package.json files under node_modules/ and vendor/ are excluded from the manifest compliance checks (the blocklist scan still covers every pnpm-lock.yaml).

Tests: the step script was run locally under the runner shell (bash --noprofile --norc -e -o pipefail) against 12 fixtures, before and after the enforcement date, and against snapshots of real repositories. pnpm workspaces (centreon, centreon-modules, centreon-pulse, centreon-cloud-apps) pass.

Impact after merge (callers use @main): repositories past their enforcement date with a package.json declaring dependencies and no lockfile will fail until fixed by their developers, e.g. Okta/tools, grafana-diagram, centreon-export, centreon-download.centreon.com (jQuery-File-Upload-master).

Out of scope, to be handled in a separate PR: exact name/version matching in the blocklist check (x@1.0.1 currently also matches x@1.0.10).

🤖 Generated with Claude Code

sc979 and others added 3 commits September 30, 2026 18:06
The lockfile version check ran in a command substitution subshell, so
the FORCE_FAIL flag set by message_type was lost: once the enforcement
date had passed, an outdated pnpm lockfile was still only reported in
the PR comment and never broke the run. Its debug output was also
captured into SKIP instead of reaching the job log.

Call compare_version directly so that it updates FORCE_FAIL and SKIP in
the current shell.

Assisted-by: Claude Code (claude-opus-5-5)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Now that compare_version runs in the current shell, the step's
`bash -e -o pipefail` aborts it when grep finds no lockfileVersion
line (empty or malformed pnpm-lock.yaml), skipping the PR comment.
Tolerate the empty match so such lockfiles keep being reported as
requiring an update.

Assisted-by: Claude Code (claude-opus-5-5)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A dependency matching the blocklist was written to the PR comment but
never broke the run, since checkPnpmLockfile did not set FORCE_FAIL. It
now always fails the build, regardless of the enforcement date.

The "A lockfile is required" check could never trigger: it sat inside
the loop over found lockfiles, which does not run when there are none.
It is now evaluated after the loop, for package.json files that declare
dependencies and are not covered by a pnpm-lock.yaml in a parent
directory (workspace members), and follows the enforcement date.

Assisted-by: Claude Code (claude-opus-5-5)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@sc979
sc979 requested a review from a team as a code owner September 30, 2026 16:46
package.json files under node_modules and vendor directories belong to
third-party code that the repository does not install from, so they
must not be required to have their own lockfile.

Assisted-by: Claude Code (claude-opus-5-5)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@sc979

sc979 commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

✅ Automated Review — Passed

This PR was reviewed using the Centreon automated review skill.

Complexity: high — Recommended reviewers: 2

No blocking issues found. Ready for human review.

Security review: no findings.

@sc979 sc979 changed the title Secu dependency analysis fix lockfile version check fix(secu): enforce dependency-analysis lockfile and blocklist checks Sep 30, 2026
@sc979
sc979 merged commit 976d758 into main Oct 1, 2026
5 checks passed
@sc979
sc979 deleted the SECU-dependencyAnalysis-fixLockfileVersionCheck branch October 1, 2026 12:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant