web-ext icon indicating copy to clipboard operation
web-ext copied to clipboard

Evaluate to only warn if a dev dependency is failing npm audit in a tagged build

Open rpl opened this issue 5 years ago • 0 comments

While releasing on npm the 3.2.1 patch release, the related travis job for the tagged release failed to reach the "npm deploy" step because of a new security advisory related to handlebars.

Ideally we should not trigger a failure in a tagged release CI job for new security advisory only related to dev dependencies, as it would prevent us to release a new version without any actual security gain for the end users, but we could let it fail in CI jobs related to pull requests (as we can easily land a patch to temporarily whitelist the security advisory and rebase the pending pull requests on top of it).

rpl avatar Nov 07 '19 14:11 rpl