Repository navigation
Commit ecfff5f
committed
fix(ci,pi): patch new Pi advisories and stop Windows hiding step failures
npm published three advisories after this stack last passed CI, failing both
Pi extension jobs introduced by the full development-tree audit:
- fast-uri <=3.1.7 and ip-address <=10.7.0 are production dependencies of
the MCP SDK. Update the Pi lockfile to fast-uri 3.1.8 and ip-address 10.7.2.
- brace-expansion <=5.0.11 exists only inside the Pi coding agent used as the
CI test host. That package ships its own npm-shrinkwrap.json, so npm
overrides cannot replace it, and no Pi release (through 0.99.1) has a fixed
lockfile yet.
Production dependencies stay strictly audited. Development advisories still
fail, except those confined to the test host's own lockfile, which are
reported as warnings until a fixed host can be adopted.
The step now runs under bash on both runners. On Windows the default pwsh
wrapper reported only the final command's exit code, so a failing npm ci,
verify or integration run was hidden whenever the audit passed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ksPGXPZQTikJYpaGHa6R61 parent a498e03 commit ecfff5f
2 files changed
Lines changed: 30 additions & 7 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
235 | 235 | | |
236 | 236 | | |
237 | 237 | | |
| 238 | + | |
| 239 | + | |
238 | 240 | | |
239 | 241 | | |
240 | 242 | | |
241 | 243 | | |
242 | 244 | | |
243 | 245 | | |
244 | | - | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
245 | 268 | | |
246 | 269 | | |
247 | 270 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments