Retry transient npm audit service failures without weakening the security gate
This commit is contained in:
parent
5ce7d8d353
commit
ab32199bd6
25
.github/workflows/qa.yml
vendored
25
.github/workflows/qa.yml
vendored
@ -14,7 +14,30 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
node-version: 22
|
node-version: 22
|
||||||
- run: npm ci
|
- run: npm ci
|
||||||
- run: npm audit --audit-level=high
|
- name: Audit dependencies (retry service errors only)
|
||||||
|
timeout-minutes: 4
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
report="$(mktemp)"
|
||||||
|
trap 'rm -f "$report"' EXIT
|
||||||
|
for attempt in 1 2 3; do
|
||||||
|
set +e
|
||||||
|
npm audit --audit-level=high --loglevel=verbose > "$report" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
cat "$report"
|
||||||
|
if [ "$status" -eq 0 ]; then exit 0; fi
|
||||||
|
# An actual vulnerability report fails immediately. A failed
|
||||||
|
# registry response is retried, never accepted as a clean audit.
|
||||||
|
if ! grep -Eq 'audit endpoint returned an error|ENOTFOUND|ECONNRESET|EAI_AGAIN|ETIMEDOUT|E429|E503' "$report"; then
|
||||||
|
exit "$status"
|
||||||
|
fi
|
||||||
|
if [ "$attempt" -eq 3 ]; then exit "$status"; fi
|
||||||
|
echo "Audit service unavailable; retry $attempt/3 after a delay."
|
||||||
|
sleep "$((attempt * 20))"
|
||||||
|
done
|
||||||
|
exit 1
|
||||||
- run: npm run check:deploy
|
- run: npm run check:deploy
|
||||||
- run: php -l public/api/index.php && php -l ops/timeweb/api-proxy.php
|
- run: php -l public/api/index.php && php -l ops/timeweb/api-proxy.php
|
||||||
- run: php tests/proxy-http.php app && php tests/proxy-http.php api
|
- run: php tests/proxy-http.php app && php tests/proxy-http.php api
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user