Skip to content

Commit d8a03c8

Browse files
committed
Merge the Pi advisory and Windows CI fix from #238 into #241
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ksPGXPZQTikJYpaGHa6R6
2 parents f10dbc4 + c28fc4f commit d8a03c8

2 files changed

Lines changed: 30 additions & 7 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 24 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -235,13 +235,36 @@ jobs:
235235
python -m pip install -e ".[test]"
236236
- name: Install and verify the Pi package
237237
working-directory: integrations/pi
238+
# Windows defaults to pwsh, which reports only the last command's exit code.
239+
shell: bash
238240
env:
239241
ENGRAPHIS_PI_TEST_COMMAND: engraphis-mcp
240242
run: |
241243
npm ci --ignore-scripts
242244
npm run verify
243245
npm run test:integration
244-
npm audit
246+
npm audit --omit=dev
247+
# Development advisories fail too, except inside the Pi test host: it ships its own
248+
# npm-shrinkwrap.json, which npm overrides cannot change. Those stay visible as
249+
# warnings until a host release with a fixed lockfile is adopted.
250+
npm audit --json > "$RUNNER_TEMP/pi-audit.json" || true
251+
python - "$RUNNER_TEMP/pi-audit.json" <<'PY'
252+
import json
253+
import sys
254+
255+
with open(sys.argv[1], encoding="utf-8") as handle:
256+
report = json.load(handle)
257+
host = "node_modules/@earendil-works/pi-coding-agent"
258+
blocking = []
259+
for name, vulnerability in sorted(report.get("vulnerabilities", {}).items()):
260+
nodes = vulnerability.get("nodes") or []
261+
if nodes and all(node == host or node.startswith(host + "/") for node in nodes):
262+
print(f"::warning::{name} ({vulnerability.get('severity')}) is pinned by the Pi test host")
263+
else:
264+
blocking.append(f"{name} ({vulnerability.get('severity')})")
265+
if blocking or "vulnerabilities" not in report:
266+
sys.exit("npm audit found development advisories: " + (", ".join(blocking) or "no report"))
267+
PY
245268
246269
browser-accessibility:
247270
name: browser accessibility smoke

‎integrations/pi/npm-shrinkwrap.json‎

Lines changed: 6 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)