From d87cb2d92fd9d39e78f0e0f63618b0ffcb469b3c Mon Sep 17 00:00:00 2001 From: Guido X Jansen Date: Wed, 4 Mar 2026 12:33:47 +0100 Subject: [PATCH] ci(api): add --prod flag to security audit (#130) Align with barazo-web by only auditing production dependencies. DevDependency vulnerabilities don't affect deployed containers. --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d4442de..9b19e7a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -136,7 +136,7 @@ jobs: - name: Security audit with retry run: | for attempt in 1 2 3; do - output=$(pnpm audit --audit-level=high 2>&1) && { echo "$output"; exit 0; } + output=$(pnpm audit --audit-level=high --prod 2>&1) && { echo "$output"; exit 0; } if echo "$output" | grep -q "ERR_PNPM_AUDIT_BAD_RESPONSE\|ECONNREFUSED\|ETIMEDOUT\|EAI_AGAIN"; then echo "::warning::Audit registry unavailable (attempt $attempt/3), retrying in 15s..." sleep 15 -- 2.51.2