Skip to content

ci(security): add SCA CVE gate for Python and docs dependencies#152

Open
tiantt wants to merge 1 commit into
mainfrom
ci/pip-audit-cve-gate
Open

ci(security): add SCA CVE gate for Python and docs dependencies#152
tiantt wants to merge 1 commit into
mainfrom
ci/pip-audit-cve-gate

Conversation

@tiantt

@tiantt tiantt commented Jul 19, 2026

Copy link
Copy Markdown
Collaborator

Adds a Software Composition Analysis gate so a vulnerable dependency can no longer silently reach main or a release (previously the only supply- chain checks were gitleaks + ruff — no CVE scanning at all).

.github/workflows/security-audit.yml runs on PR, push to main, a weekly schedule, and manual dispatch:

  • pip-audit --strict on requirements.txt (the shipped SDK deps). Currently clean; an escape hatch lives in .pip-audit-ignore (advisory IDs with a mandatory written justification).
  • npm audit on the docs/ VitePress toolchain, gating at critical. The tree is build-time-only (never in the PyPI wheel); all advisories are also printed non-blocking for visibility.

Also:

  • npm audit fix on docs/package-lock.json clears 3 of 6 advisories (semver-safe). The residual 3 are dev-server-only (vite/esbuild via vitepress) with no fix on the current stable line; left for a future vitepress major bump.
  • pip-audit>=2.7.0 added to the dev dependency group for local runs.

Adds a Software Composition Analysis gate so a vulnerable dependency can
no longer silently reach main or a release (previously the only supply-
chain checks were gitleaks + ruff — no CVE scanning at all).

.github/workflows/security-audit.yml runs on PR, push to main, a weekly
schedule, and manual dispatch:
- pip-audit --strict on requirements.txt (the shipped SDK deps). Currently
  clean; an escape hatch lives in .pip-audit-ignore (advisory IDs with a
  mandatory written justification).
- npm audit on the docs/ VitePress toolchain, gating at critical. The tree
  is build-time-only (never in the PyPI wheel); all advisories are also
  printed non-blocking for visibility.

Also:
- npm audit fix on docs/package-lock.json clears 3 of 6 advisories
  (semver-safe). The residual 3 are dev-server-only (vite/esbuild via
  vitepress) with no fix on the current stable line; left for a future
  vitepress major bump.
- pip-audit>=2.7.0 added to the dev dependency group for local runs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant