From 74a501b08777cf58d13c44adae25530a78e3120e Mon Sep 17 00:00:00 2001 From: Alexei Lozovsky Date: Wed, 9 Jun 2021 18:25:52 +0900 Subject: [PATCH] Resolve audit warnings (#45) * Update glob-parent to resolve CVE-2020-28469 * Run audit tasks on Ubuntu runners (they are cheaper) * Audit only production dependencies That is, something that can actually affect users of this action. I don't really want to be bothered with yet another "prototype pollution" or "denial of service" in transitive dependencies of eslint. * Audit dev-dependencies for critical vulnerabilities That said, still audit development dependencies for critical vulnerabilities if they come along. Hopefully, this should be rare. --- .github/workflows/main.yml | 5 +++-- .github/workflows/release.yml | 5 +++-- package-lock.json | 12 ++++++------ 3 files changed, 12 insertions(+), 10 deletions(-) diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index d0e4aeb..e37f122 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -58,12 +58,13 @@ jobs: dumpbin /headers hello.exe audit: name: npm audit - runs-on: windows-latest + runs-on: ubuntu-latest steps: - name: Check out source code uses: actions/checkout@v2 - run: npm install - - run: npm audit --audit-level=moderate + - run: npm audit --audit-level=moderate --production + - run: npm audit --audit-level=critical alias-arch: name: arch aliases runs-on: windows-latest diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index e9c853f..08b856b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -23,8 +23,9 @@ jobs: hello.exe audit: name: npm audit - runs-on: windows-latest + runs-on: ubuntu-latest steps: - name: Check out source code uses: actions/checkout@v2 - - run: npm audit --audit-level=moderate + - run: npm audit --audit-level=moderate --production + - run: npm audit --audit-level=critical diff --git a/package-lock.json b/package-lock.json index 3735354..70a4bd2 100644 --- a/package-lock.json +++ b/package-lock.json @@ -531,9 +531,9 @@ } }, "node_modules/glob-parent": { - "version": "5.1.0", - "resolved": "https://registry.npmjs.org/glob-parent/-/glob-parent-5.1.0.tgz", - "integrity": "sha512-qjtRgnIVmOfnKUE3NJAQEdk+lKrxfw8t5ke7SXtfMTHcjsBfOfWXCQfdb30zfDoZQ2IRSIiidmjtbHZPZ++Ihw==", + "version": "5.1.2", + "resolved": "https://registry.npmjs.org/glob-parent/-/glob-parent-5.1.2.tgz", + "integrity": "sha512-AOIgSQCepiJYwP3ARnGx+5VnTu2HBYdzbGP45eLw1vr3zB3vZLeyed1sC9hnbcOc9/SrMyM5RPQrkGz4aS9Zow==", "dev": true, "dependencies": { "is-glob": "^4.0.1" @@ -1690,9 +1690,9 @@ } }, "glob-parent": { - "version": "5.1.0", - "resolved": "https://registry.npmjs.org/glob-parent/-/glob-parent-5.1.0.tgz", - "integrity": "sha512-qjtRgnIVmOfnKUE3NJAQEdk+lKrxfw8t5ke7SXtfMTHcjsBfOfWXCQfdb30zfDoZQ2IRSIiidmjtbHZPZ++Ihw==", + "version": "5.1.2", + "resolved": "https://registry.npmjs.org/glob-parent/-/glob-parent-5.1.2.tgz", + "integrity": "sha512-AOIgSQCepiJYwP3ARnGx+5VnTu2HBYdzbGP45eLw1vr3zB3vZLeyed1sC9hnbcOc9/SrMyM5RPQrkGz4aS9Zow==", "dev": true, "requires": { "is-glob": "^4.0.1"