diff --git a/apps/docs/content/docs/security.md b/apps/docs/content/docs/security.md index 9a129ce..9d3eea2 100644 --- a/apps/docs/content/docs/security.md +++ b/apps/docs/content/docs/security.md @@ -2,7 +2,7 @@ ## Dependency review -The CI pipeline runs `pnpm audit --prod --audit-level high` on every push (`ci/pipeline.ts`). High and critical advisories fail the build. Moderate and below stay informational and are reviewed during release prep. +The CI pipeline runs `pnpm audit --prod --audit-level moderate` on every push (`ci/pipeline.ts`). Moderate, high, and critical advisories all fail the build (we're currently at zero known across all severities, so a fresh moderate is signal worth catching at PR time). Drop the gate back to `high` only if a long-tail moderate appears upstream that can't be cleared. ### How transitive advisories were cleared (CVG-47) diff --git a/ci/pipeline.ts b/ci/pipeline.ts index 9b45aab..f89cdee 100644 --- a/ci/pipeline.ts +++ b/ci/pipeline.ts @@ -14,12 +14,14 @@ const steps: Step[] = [ { name: "Lint", command: "pnpm lint" }, { name: "Typecheck", command: "pnpm typecheck" }, { name: "Build", command: "pnpm build" }, - // Production-dependency advisory check (CVG-46). Gated at high - moderate - // and below stay informational so a fresh moderate doesn't break the build, - // but anything high or critical fails fast. + // Production-dependency advisory check (CVG-46). Gated at moderate - + // we're at zero known advisories across all severities (CVG-47), so a + // fresh moderate is something we want to know about before merge. + // Drop back to "high" if a long-tail moderate appears that can't be + // cleared without an upstream fix. { name: "Security audit", - command: "pnpm audit --prod --audit-level high", + command: "pnpm audit --prod --audit-level moderate", }, ];