ci: add CVE Lite dependency audit workflow - #2819
Conversation
|
|
One quick note: CVE Lite CLI v1.26.0 shipped a scheduled fix mode that can automate what the companion fix PR does manually. Adding Want me to update this PR to include that? It does require enabling "Allow GitHub Actions to create and approve pull requests" in your repo settings first. |
|
@ryansolid With 2.0 RC out, wanted to gently check back in on this one. It wires a lightweight dependency audit into CI so vulnerable deps get surfaced on PRs before a release, and it's config-driven so you can set the severity threshold or turn off the fail gate to fit your flow. I just bumped the pinned action to our latest release so it's current and ready to go. Totally understand if it's not a priority with everything else on your plate right now. |
This PR adds a CVE Lite dependency audit workflow to help catch vulnerable dependencies before they land in main.
CVE Lite CLI is an OWASP Lab Project that scans lockfiles locally without installing packages. It reads the pnpm lockfile directly, queries the OSV vulnerability database, and classifies findings as direct or transitive so you know exactly what you control. A scan of the current main branch found 34 findings total - 3 critical, 16 high, 14 medium, and 1 low.
The workflow runs on every push to main, every pull request targeting main, and on a weekly schedule every Monday morning. When vulnerabilities at high severity or above are found, the job fails so they do not go unnoticed in CI. Results are also exported as a SARIF file and uploaded to GitHub Code Scanning, which surfaces findings directly on the Security tab with file and line context.
All Actions are pinned to immutable commit SHAs rather than mutable version tags, so the supply chain for the workflow itself is locked down.
A companion PR with direct dependency upgrades is coming separately once this is reviewed.
Full documentation and the OWASP project page are at https://owasp.org/cve-lite-cli