Repository navigation
ci: report pnpm audit findings to code scanning - #7698
Conversation
Co-Authored-By: Claude Opus 5.5 <michael.kriese+claude-code@mend.io>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 11 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Summary by QodoReport pnpm audit advisories in GitHub code scanning
AI Description
Diagram
High-Level Assessment
Files changed (3)
|
Code Review by Qodo
1. Scoped package alerts point to the wrong line
|
Changes
Adds a
pnpm-auditworkflow that uploads thepnpm auditadvisories of the root lockfile to code scanning, like the trivy workflow does for the image:mainthat changepnpm-lock.yaml, and on demandtools/audit-sarif.tsconverts thepnpm audit --jsonreport to SARIF: one rule per GHSA advisory with its code scanning severity, one result per vulnerable version, pointing at the package entry inpnpm-lock.yaml; it fails when pnpm returns an error instead of a reportThe dependency graph currently reads only the first document of pnpm 12's lockfile, so Dependabot doesn't alert on the root dependencies (dependabot-core#15904). The workflow can go once that's fixed.
Context
Please select one of the following:
AI assistance disclosure
Did you use AI tools to create any part of this pull request?
Please select one option and, if yes, briefly describe how AI was used (e.g., code, tests, docs) and which tool(s) you used.
Written by Claude Opus 5.5 in Claude Code.
Use of AI in replying to PR comments
Who answers review comments:
Documentation (please check one with an [x])
How I've tested my work (please select one)
I have verified these changes via:
Converted the current
pnpm audit --jsonreport locally (5 advisories, each pointing at its lockfile entry) and checked the workflows with jactionlint. The upload itself runs once the workflow is onmain(workflow_dispatch).🤖 Generated with Claude Code