Skip to content

Audit dependencies in CI, pin sharp 0.35.5, parse workflow YAML with Bun - #2

Merged
Finesssee merged 1 commit into
mainfrom
chore/bun-audit
Oct 8, 2026
Merged

Finesssee merged 1 commit into
mainfrom
chore/bun-audit

Conversation

@Finesssee

@Finesssee Finesssee commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator
  • bun run audit (bun audit --audit-level=high) runs in CI after the build; fails on a high or critical advisory.
  • overrides.sharp = 0.35.5 fixes CVE-2026-96889 (GHSA-wq5f-xc86-pv6w). miniflare pins sharp 0.35.4 exactly, so bun audit fix can't reach it. 0.35.5 was published 2026-09-27, past the 7-day age rule. sharp only runs in local dev/build, not in the Worker.
  • The workflow tests parse YAML with Bun.YAML instead of python/PyYAML, so they can't skip silently any more (that skip hid a broken test earlier).
  • Docs: DEVELOPMENT.md, CONTRACTS.md §9, LIVE_FIX.md.

bun run check: 304 pass, 0 skipped. bun run audit: no vulnerabilities.

Summary by CodeRabbit

  • Chores
    • Added a dependency audit to automated checks. Builds now fail when installed packages have high- or critical-severity advisories.
    • Updated the sharp package version override.
  • Documentation
    • Updated build and development instructions with audit details and guidance for reviewing dependency changes.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: nesszer/pixfray/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c700a038-4264-485b-9bf1-ea6b9d3db66f
📥 Commits

Reviewing files that changed from the base of the PR and between 3219eaa and 15dc832.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock, !bun.lock
📒 Files selected for processing (6)
  • .github/workflows/ci.yml
  • docs/CONTRACTS.md
  • docs/DEVELOPMENT.md
  • docs/LIVE_FIX.md
  • package.json
  • tests/dev-release.test.mjs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The package adds a high-severity dependency audit command and pins sharp to 0.35.5. CI runs the audit, and workflow tests validate the step using Bun’s YAML parser. The workflow description now says checks run for every pull request; triggers remain unchanged.

Changes

Dependency Audit

Layer / File(s) Summary
Audit command and dependency guidance
package.json, docs/CONTRACTS.md, docs/DEVELOPMENT.md
Adds bun run audit with a high-severity threshold and pins sharp to 0.35.5. Documentation describes the audit threshold, dependency overrides, and package version comparisons.
CI enforcement and workflow validation
.github/workflows/ci.yml, docs/LIVE_FIX.md, tests/dev-release.test.mjs
CI runs the audit command. Tests use Bun’s YAML parser, fail if Bun or parsing fails, and assert that the CI job runs the audit.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 15dc8

The checked-in lockfile resolves the patched sharp release, and CI installs it reproducibly before auditing dependencies. No concrete merge-blocking risk is established by the reviewed changes.

🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: CI dependency auditing, the sharp override, and Bun-based YAML parsing. It is specific and concise.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Behavior Change Has A Test And Docs ✅ Passed The PR changes only CI, dependency metadata/lockfile, documentation, and tests/dev-release.test.mjs. The authoritative diff has no changed files under server/, src/, or public/, so the require…
Config Lives In Site.Config.Js ✅ Passed No prohibited hard-coded value was introduced. The changed non-exempt files add only the CI audit command and the sharp 0.35.5 dependency override/lockfile entries. The Twitch logins, Worker names, …
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

- bun run audit (bun audit --audit-level=high) runs in CI after the build.
- Override sharp to 0.35.5 for CVE-2026-96889; miniflare pins 0.35.4 exactly.
- The workflow tests parse YAML with Bun.YAML instead of python/PyYAML, so they
  no longer skip silently when PyYAML is missing.
- Document the audit, overrides and bun pm diff.
@Finesssee

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@Finesssee
Finesssee merged commit 93e1f82 into main Oct 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant