Reconsider `npm audit --audit-level=high` as a hard CI gate
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Refactor
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- github-actions, typescript
Research direction
Start by locating the CI workflow that runs npm audit --audit-level=high and review how the Expo dependency tree is checked. Compare the current hard gate with continue-on-error: true, then make the selected tradeoff explicit in the workflow and verify that unrelated pull requests behave as intended.
Written by the indexing model from the issue text.
Description
As currently configured, this will block unrelated PRs the day a high advisory lands anywhere in Expo's dependency tree. continue-on-error: true is the alternative tradeoff, worth a deliberate choice either way.
- Dominant language
- TypeScript
- Stars
- 9
- Forks
- 4
- Avg merge
- 9h 34m
- Merged PRs (30d)
- 16
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from rubyforgood/alongwithyou
-
bug RFG Conference ruby severity:minor triage
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
rubyforgood/alongwithyou#173 ·
-
needs-verification
Difficulty 1/5 Under an hour Newbie friendliness 72/100
rubyforgood/alongwithyou#100 ·
-
needs-verification
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
rubyforgood/alongwithyou#99 ·
-
severity:minor
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
rubyforgood/alongwithyou#95 ·
-
good first issue severity:minor
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
rubyforgood/alongwithyou#93 ·
All issues in rubyforgood/alongwithyou
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
bug clawsweeper:linked-pr-open clawsweeper:needs-live-repro clawsweeper:no-new-fix-pr impact:message-loss issue-rating: 🐚 platinum hermit P2 regression
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
calcite-components needs triage refactor
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Esri/calcite-design-system#15203 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
danielmiessler/LifeOS#2218 ·