Skip to content

ci: review dependency vulnerabilities on pull requests - #22

Open
zoeyrose wants to merge 2 commits into
mainfrom
ci/dependency-review
Open

zoeyrose wants to merge 2 commits into
mainfrom
ci/dependency-review

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Oct 11, 2026 •

Copy link
Copy Markdown
Member

Summary

Add a dependency review check for pull requests targeting main. Newly introduced high or critical vulnerable dependencies fail the check.

Implementation / behavior

The dedicated Dependency review job uses the official action with read-only repository permissions and reviews runtime, development, and unknown dependency scopes. It runs for every pull request, including Dependabot and fork contributions, without checking out or executing PR code. Lower-severity findings do not block the check.

The workflow uses a full action commit SHA that Dependabot can update normally; it adds no separate approved-version list, license gate, or human-approval requirement.

Validation

  • Actionlint and whitespace checks passed.
  • Independent review confirmed the workflow trigger, permissions, inputs, and action reference.

Limitations / follow-up

The full local validator passed. Live fork/Dependabot acceptance and required-check enforcement remain pending the coordinated governance rollout.

Automated review follow-up

Dependency review now handles PR retargeting and merge queue groups. The official action uses the appropriate event revisions without checking out or executing contributor code. Fresh CI and Codex code/security reviews are required at this updated head.

Release-tool dependencies are declared in a private npm manifest and standard lockfile, installed using npm ci, and updated through grouped npm Dependabot PRs. Direct release-tool versions and release behavior are preserved. SHA-pinned Actions advisory coverage remains limited by GitHub; no custom resolver or parallel pin catalog is introduced.

Deferred merge: upstream release-tool advisories

Dependency review correctly rejects the now-visible release tool graph. The existing semantic-release toolchain bundles brace-expansion 5.0.9 through npm 11.21.0, affecting GHSA-6j4f-fj2g-mc7p and GHSA-qhr7-859c-m2p7. Ordinary compatible updates do not replace the bundled package. Independent audit also found unpatched braces GHSA-vfj7-8cjw-p6xm and additional high bundled-tool advisories.

Leave this PR unmerged until compatible upstream fixes are available and current-head Dependency review and Codex code/security reviews pass. No advisory exceptions, reduced scope, warn-only setting, or graph hiding are authorized. Standard manifest/lock and grouped Dependabot maintenance remain intact for the eventual fixes.

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-11T16:52:27.006753Z a5a789a Manual request
🔒 Security Review ✅ Completed 2026-10-11T16:57:08.859630Z a5a789a Manual request

Security findings

Advisory findings (1)

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 283b919d0a

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 283b919d0a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/dependency-review.yml

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: a5a789a7c1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

Here are some automated security review suggestions for this pull request.

Reviewed commit: a5a789a7c1

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

Comment on lines +6 to +7
branches:
- main

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

P2 Badge Security: Cover maintenance branches with dependency review

If a PR targets a supported maintenance branch such as 8.3.x and that branch is not forced through a merge queue, this main-only filter prevents the dependency-review job from being created. Yet release.yml releases every [0-9]+.[0-9]+.x push and installs/runs the PR-controlled lockfile with a write-scoped token. If accepted, a contributor's high/critical vulnerable release dependency can therefore reach this unreviewed path. Add the maintenance pattern here and require the check there. merge_group mitigates only branches that mandate queues; active branches and hosted protections remain unknown.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant