chore(ci): add npm-audit-fix workflow#3496
Open
AlexanderBarabanov wants to merge 3 commits intomainfrom
Open
Conversation
Signed-off-by: Barabanov, Alexander <alexander.barabanov@intel.com>
Signed-off-by: Barabanov, Alexander <alexander.barabanov@intel.com>
Contributor
There was a problem hiding this comment.
Pull request overview
This PR introduces an automated dependency-remediation workflow for the UI’s NPM dependencies and adjusts the reusable security scan workflow to avoid duplicative Trivy vulnerability scanning.
Changes:
- Add a scheduled + manually-triggerable
npm audit fixGitHub Actions workflow that can open PRs whenapplication/uilockfiles change. - Disable the
vulnscanner in the Trivy filesystem scan configuration (keepingsecretandconfig).
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
.github/workflows/npm-audit-fix.yml |
New workflow to run npm audit / npm audit fix in application/ui and open an automated PR when it changes lockfiles. |
.github/workflows/_reusable-security-scan.yaml |
Update Trivy FS scan configuration to exclude vulnerability scanning. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Docker Image SizesCPU
CUDA
XPU
|
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📝 Description
This PR adds a new scheduled workflow
.github/workflows/npm-audit-fix.ymlto automatically runnpm audit fixon a schedule or on demand (with optional--forceflag).Also,
vulntype scan has been disabled intrivyfilesystem scan as Dependabot is able to detect similar issue (duplication).✨ Changes
Select what type of change your PR is:
✅ Checklist
Before you submit your pull request, please make sure you have completed the following steps:
For more information about code review checklists, see the Code Review Checklist.