Skip to content

ci: report pnpm audit findings to code scanning - #7698

Merged
viceice merged 1 commit into
mainfrom
viceice/ci/pnpm-audit-code-scanning
Oct 9, 2026
Merged

viceice merged 1 commit into
mainfrom
viceice/ci/pnpm-audit-code-scanning

Conversation

@viceice

@viceice viceice commented Oct 9, 2026

Copy link
Copy Markdown
Member

Changes

Adds a pnpm-audit workflow that uploads the pnpm audit advisories of the root lockfile to code scanning, like the trivy workflow does for the image:

  • runs daily, on pushes to main that change pnpm-lock.yaml, and on demand
  • tools/audit-sarif.ts converts the pnpm audit --json report to SARIF: one rule per GHSA advisory with its code scanning severity, one result per vulnerable version, pointing at the package entry in pnpm-lock.yaml; it fails when pnpm returns an error instead of a report
  • pull requests that only change the new workflow, the script or the trivy workflow skip the build and docker tests, like the other lint tools

The dependency graph currently reads only the first document of pnpm 12's lockfile, so Dependabot doesn't alert on the root dependencies (dependabot-core#15904). The workflow can go once that's fixed.

Context

Please select one of the following:

  • This closes an existing Issue, Closes: #
  • This doesn't close an Issue, but I accept the risk that this PR may be closed if maintainers disagree with its opening or implementation

AI assistance disclosure

Did you use AI tools to create any part of this pull request?

Please select one option and, if yes, briefly describe how AI was used (e.g., code, tests, docs) and which tool(s) you used.

  • No — I did not use AI for this contribution.
  • Yes — minimal assistance (e.g., IDE autocomplete, small code completions, grammar fixes).
  • Yes — substantive assistance (AI-generated non‑trivial portions of code, tests, or documentation).
  • Yes — other (please describe):

Written by Claude Opus 5.5 in Claude Code.

Use of AI in replying to PR comments

Who answers review comments:

  • @viceice will read and reply directly. Name the account.
  • An agent will draft replies and @username will read them before they are posted. Name the account.
  • An agent will draft replies and reply autonomously. This is heavily discouraged, and we prefer that there are humans in the loop
  • Nobody has explicitly committed to replying.

Documentation (please check one with an [x])

  • I have updated the documentation, or
  • No documentation update is required

How I've tested my work (please select one)

I have verified these changes via:

  • Code inspection only, or
  • Newly added/modified tests

Converted the current pnpm audit --json report locally (5 advisories, each pointing at its lockfile entry) and checked the workflows with jactionlint. The upload itself runs once the workflow is on main (workflow_dispatch).

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <michael.kriese+claude-code@mend.io>
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 11 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: containerbase/coderabbit/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f46802e7-38d0-4174-a87d-68a1757b3fac

📥 Commits

Reviewing files that changed from the base of the PR and between 2533378 and 31d6b51.


📒 Files selected for processing (3)
  • .github/workflows/build.yml
  • .github/workflows/pnpm-audit.yml
  • tools/audit-sarif.ts


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@viceice
viceice enabled auto-merge October 9, 2026 10:01
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Report pnpm audit advisories in GitHub code scanning

✨ Enhancement ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Add scheduled, lockfile-triggered, and manual scans to surface root dependency advisories in code
 scanning.
• Convert pnpm audit reports into SARIF findings linked to vulnerable lockfile entries.
• Skip build and Docker tests for PRs changing only the audit tooling or Trivy workflow.
Diagram

graph TD
  T["Scheduled, push, manual"] --> W["Audit workflow"] --> A["pnpm audit"] --> C["SARIF converter"] --> S["SARIF report"] --> G["Code scanning"]
  L["Root lockfile"] --> A
  L --> C
Loading
High-Level Assessment

The targeted pnpm-to-SARIF bridge is appropriate while the dependency graph cannot read the root dependencies in pnpm’s two-document lockfile. Waiting for Dependabot support would leave that visibility gap; adopting another scanner would change the advisory source and add a dependency for a small conversion task. Verify the code scanning upload after the workflow reaches main.

Files changed (3) +164 / -1

Enhancement (2) +162 / -0
pnpm-audit.ymlRun pnpm audits and upload SARIF findings +41/-0

Run pnpm audits and upload SARIF findings

• Adds a daily, main-branch lockfile-change, and manually triggered workflow. It runs pnpm audit, converts its JSON report to SARIF, and uploads the result to GitHub code scanning with security-events permission.

.github/workflows/pnpm-audit.yml

audit-sarif.tsConvert pnpm advisories into lockfile-linked SARIF +121/-0

Convert pnpm advisories into lockfile-linked SARIF

• Creates a SARIF rule per GHSA advisory and a result per vulnerable version, with severity metadata and a location in pnpm-lock.yaml. Rejects audit error objects instead of uploading them as empty reports.

tools/audit-sarif.ts

Other (1) +2 / -1
build.ymlExclude audit-only changes from build and Docker tests +2/-1

Exclude audit-only changes from build and Docker tests

• Expands the PR-only skip-build filter to include the SARIF converter and the pnpm-audit and Trivy workflows. Changes limited to those files can bypass the build and Docker tests while other checks remain available.

.github/workflows/build.yml

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1)

Grey Divider


Remediation recommended

1. Scoped package alerts point to the wrong line 🐞 Bug
Description
lockfileLine searches for an unquoted package key, while pnpm quotes scoped package keys in
pnpm-lock.yaml. When an advisory affects a scoped package, the search misses its entry and places
the code-scanning result on line 1 instead.
Code

tools/audit-sarif.ts[R62-64]

+  const entry = `  ${name}@${version}:`;
+  const index = lines.findIndex((line) => line.startsWith(entry));
+  return index === -1 ? 1 : index + 1;
Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Scoped package keys are quoted in the pnpm lockfile, so the converter places their alerts on line 1 rather than on the package entry.
## Fix Focus Areas
- tools/audit-sarif.ts[60-65]
## Recommended Fix
Match pnpm's quoted key format for scoped packages as well as its unquoted format for other packages. Add a converter test using a scoped package entry.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗


Grey Divider

Tip of the day
💡 Did you know, you can show, collapse, or hide each part of a finding: code, evidence, and all

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@viceice
viceice added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit e5ff814 Oct 9, 2026
61 checks passed
@viceice
viceice deleted the viceice/ci/pnpm-audit-code-scanning branch October 9, 2026 11:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant