Repository navigation
fix(secu): enforce dependency-analysis lockfile and blocklist checks - #73
Merged
Merged
Conversation
The lockfile version check ran in a command substitution subshell, so the FORCE_FAIL flag set by message_type was lost: once the enforcement date had passed, an outdated pnpm lockfile was still only reported in the PR comment and never broke the run. Its debug output was also captured into SKIP instead of reaching the job log. Call compare_version directly so that it updates FORCE_FAIL and SKIP in the current shell. Assisted-by: Claude Code (claude-opus-5-5) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Now that compare_version runs in the current shell, the step's `bash -e -o pipefail` aborts it when grep finds no lockfileVersion line (empty or malformed pnpm-lock.yaml), skipping the PR comment. Tolerate the empty match so such lockfiles keep being reported as requiring an update. Assisted-by: Claude Code (claude-opus-5-5) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A dependency matching the blocklist was written to the PR comment but never broke the run, since checkPnpmLockfile did not set FORCE_FAIL. It now always fails the build, regardless of the enforcement date. The "A lockfile is required" check could never trigger: it sat inside the loop over found lockfiles, which does not run when there are none. It is now evaluated after the loop, for package.json files that declare dependencies and are not covered by a pnpm-lock.yaml in a parent directory (workspace members), and follows the enforcement date. Assisted-by: Claude Code (claude-opus-5-5) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
package.json files under node_modules and vendor directories belong to third-party code that the repository does not install from, so they must not be required to have their own lockfile. Assisted-by: Claude Code (claude-opus-5-5) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
✅ Automated Review — PassedThis PR was reviewed using the Centreon automated review skill. Complexity: high — Recommended reviewers: 2 No blocking issues found. Ready for human review.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
What are your needs or what are you planning to do in this PR?
🤖 Generated with Claude Code