@@ -235,13 +235,36 @@ jobs:
235235 python -m pip install -e ".[test]"
236236 - name : Install and verify the Pi package
237237 working-directory : integrations/pi
238+ # Windows defaults to pwsh, which reports only the last command's exit code.
239+ shell : bash
238240 env :
239241 ENGRAPHIS_PI_TEST_COMMAND : engraphis-mcp
240242 run : |
241243 npm ci --ignore-scripts
242244 npm run verify
243245 npm run test:integration
244- npm audit
246+ npm audit --omit=dev
247+ # Development advisories fail too, except inside the Pi test host: it ships its own
248+ # npm-shrinkwrap.json, which npm overrides cannot change. Those stay visible as
249+ # warnings until a host release with a fixed lockfile is adopted.
250+ npm audit --json > "$RUNNER_TEMP/pi-audit.json" || true
251+ python - "$RUNNER_TEMP/pi-audit.json" <<'PY'
252+ import json
253+ import sys
254+
255+ with open(sys.argv[1], encoding="utf-8") as handle:
256+ report = json.load(handle)
257+ host = "node_modules/@earendil-works/pi-coding-agent"
258+ blocking = []
259+ for name, vulnerability in sorted(report.get("vulnerabilities", {}).items()):
260+ nodes = vulnerability.get("nodes") or []
261+ if nodes and all(node == host or node.startswith(host + "/") for node in nodes):
262+ print(f"::warning::{name} ({vulnerability.get('severity')}) is pinned by the Pi test host")
263+ else:
264+ blocking.append(f"{name} ({vulnerability.get('severity')})")
265+ if blocking or "vulnerabilities" not in report:
266+ sys.exit("npm audit found development advisories: " + (", ".join(blocking) or "no report"))
267+ PY
245268
246269 browser-accessibility :
247270 name : browser accessibility smoke
0 commit comments