@@ -241,30 +241,15 @@ jobs:
241241 ENGRAPHIS_PI_TEST_COMMAND : engraphis-mcp
242242 run : |
243243 npm ci --ignore-scripts
244+ # The test host's published shrinkwrap overrides this package's nested pin.
245+ # Repair that exact leaf in the installed host, preserving its other locked deps.
246+ # --omit=dev excludes the host's own authoring tools, not this package's test tools.
247+ npm install --prefix node_modules/@earendil-works/pi-coding-agent --ignore-scripts --no-save --omit=dev brace-expansion@5.0.12
248+ node -e "require('node:assert/strict').equal(require('./node_modules/@earendil-works/pi-coding-agent/node_modules/brace-expansion/package.json').version, '5.0.12')"
244249 npm run verify
245250 npm run test:integration
246- npm audit --omit=dev
247- # Development advisories fail too, except inside the Pi test host: it ships its own
248- # npm-shrinkwrap.json, which npm overrides cannot change. Those stay visible as
249- # warnings until a host release with a fixed lockfile is adopted.
250- npm audit --json > "$RUNNER_TEMP/pi-audit.json" || true
251- python - "$RUNNER_TEMP/pi-audit.json" <<'PY'
252- import json
253- import sys
254-
255- with open(sys.argv[1], encoding="utf-8") as handle:
256- report = json.load(handle)
257- host = "node_modules/@earendil-works/pi-coding-agent"
258- blocking = []
259- for name, vulnerability in sorted(report.get("vulnerabilities", {}).items()):
260- nodes = vulnerability.get("nodes") or []
261- if nodes and all(node == host or node.startswith(host + "/") for node in nodes):
262- print(f"::warning::{name} ({vulnerability.get('severity')}) is pinned by the Pi test host")
263- else:
264- blocking.append(f"{name} ({vulnerability.get('severity')})")
265- if blocking or "vulnerabilities" not in report:
266- sys.exit("npm audit found development advisories: " + (", ".join(blocking) or "no report"))
267- PY
251+ npm audit
252+ npm audit --no-package-lock --include=dev
268253
269254 browser-accessibility :
270255 name : browser accessibility smoke
0 commit comments