chore(deps): pin Angular to 22.0.5 and gate audit at high
CI / changes (push) Successful in 7s
CI / lint (push) Successful in 1m57s
CI / frontend (push) Successful in 2m45s
CI / backend (push) Successful in 1m57s
CI / e2e (push) Failing after 4m10s
CI / semgrep (push) Successful in 1m18s
CI / api-client-drift (push) Successful in 2m9s
CI / storybook-a11y (push) Successful in 11m5s
CI / changes (push) Successful in 7s
CI / lint (push) Successful in 1m57s
CI / frontend (push) Successful in 2m45s
CI / backend (push) Successful in 1m57s
CI / e2e (push) Failing after 4m10s
CI / semgrep (push) Successful in 1m18s
CI / api-client-drift (push) Successful in 2m9s
CI / storybook-a11y (push) Successful in 11m5s
Angular 22.1.x emits `var(--%NS%name)` for every CSS custom property in a component `styles:` block. No `@angular/core` release substitutes the placeholder, so all `--rhc-*` tokens resolve to nothing and the UI breaks. `npm run ci` does not catch it; only the Storybook axe job does. Pin every `@angular*` entry to the exact version 22.0.5, so a plain `npm install` cannot pull 22.1.x back in. Holding at 22.0.5 leaves three moderate advisories open, which made the audit step fail: GHSA-p297-fm68-3q8c and GHSA-hh8m-fm6v-7cvg. Neither is reachable. The app calls no `withRequestsMadeViaParent` and no `provideClientHydration`, and binds no untrusted value into a directive host binding. The audit gate therefore runs at `--audit-level=high`. A high advisory still fails the build. Restore the default audit level together with the upgrade, after an Angular release substitutes the placeholder. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -124,8 +124,15 @@ jobs:
|
|||||||
# app's messages.en.xlf is missing a unit its source (WP-20) or libs/shared gains.
|
# app's messages.en.xlf is missing a unit its source (WP-20) or libs/shared gains.
|
||||||
- run: npx ng build ssp --localize && npx ng build behandelportal --localize
|
- run: npx ng build ssp --localize && npx ng build behandelportal --localize
|
||||||
if: needs.changes.outputs.frontend == 'true'
|
if: needs.changes.outputs.frontend == 'true'
|
||||||
# The shipped bundle must stay clean; dev-only advisories are excluded.
|
# The shipped bundle must stay clean; dev-only advisories are excluded. The gate is
|
||||||
- run: npm audit --omit=dev
|
# `high`, not the default `low`, because two moderate Angular advisories stay open
|
||||||
|
# while we hold at 22.0.5: GHSA-p297-fm68-3q8c and GHSA-hh8m-fm6v-7cvg. Neither is
|
||||||
|
# reachable — the app calls no `withRequestsMadeViaParent` and no
|
||||||
|
# `provideClientHydration`, and binds no untrusted value into a directive host
|
||||||
|
# binding. The fix is Angular 22.1.x, which emits `var(--%NS%name)` and breaks every
|
||||||
|
# `--rhc-*` token. Restore `low` after an Angular release substitutes the
|
||||||
|
# placeholder; verify with `grep -rl '%NS%' dist/` after `npm run build`.
|
||||||
|
- run: npm audit --omit=dev --audit-level=high
|
||||||
if: needs.changes.outputs.frontend == 'true'
|
if: needs.changes.outputs.frontend == 'true'
|
||||||
|
|
||||||
storybook-a11y:
|
storybook-a11y:
|
||||||
|
|||||||
@@ -58,7 +58,10 @@ catches a miss before CI does.
|
|||||||
|
|
||||||
`.npmrc` sets `legacy-peer-deps=true` (Storybook's peer range lags Angular 22).
|
`.npmrc` sets `legacy-peer-deps=true` (Storybook's peer range lags Angular 22).
|
||||||
Do not run `npm audit fix --force` — it downgrades Angular 22→21. Dev-only
|
Do not run `npm audit fix --force` — it downgrades Angular 22→21. Dev-only
|
||||||
advisories are pinned via `package.json` `overrides`; the shipped bundle audits clean.
|
advisories are pinned via `package.json` `overrides`. Angular is pinned to the exact
|
||||||
|
version 22.0.5: 22.1.x emits `var(--%NS%name)` and breaks every `--rhc-*` token, so the
|
||||||
|
two moderate advisories it fixes stay open. Neither is reachable, so the audit gate runs
|
||||||
|
at `--audit-level=high` (see the comment in `ci.yml`).
|
||||||
|
|
||||||
## Model routing for agent delegation
|
## Model routing for agent delegation
|
||||||
|
|
||||||
|
|||||||
Generated
+14
-14
@@ -8,24 +8,24 @@
|
|||||||
"name": "atomic-design-poc",
|
"name": "atomic-design-poc",
|
||||||
"version": "0.0.0",
|
"version": "0.0.0",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@angular/common": "^22.0.0",
|
"@angular/common": "22.0.5",
|
||||||
"@angular/compiler": "^22.0.0",
|
"@angular/compiler": "22.0.5",
|
||||||
"@angular/core": "^22.0.0",
|
"@angular/core": "22.0.5",
|
||||||
"@angular/forms": "^22.0.0",
|
"@angular/forms": "22.0.5",
|
||||||
"@angular/platform-browser": "^22.0.0",
|
"@angular/platform-browser": "22.0.5",
|
||||||
"@angular/router": "^22.0.0",
|
"@angular/router": "22.0.5",
|
||||||
"rxjs": "~7.8.0",
|
"rxjs": "~7.8.0",
|
||||||
"tslib": "^2.3.0"
|
"tslib": "^2.3.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@angular-devkit/architect": "^0.2200.0",
|
"@angular-devkit/architect": "0.2200.5",
|
||||||
"@angular-devkit/build-angular": "^22.0.0",
|
"@angular-devkit/build-angular": "22.0.5",
|
||||||
"@angular-devkit/core": "^22.0.0",
|
"@angular-devkit/core": "22.0.5",
|
||||||
"@angular/build": "^22.0.4",
|
"@angular/build": "22.0.5",
|
||||||
"@angular/cli": "^22.0.4",
|
"@angular/cli": "22.0.5",
|
||||||
"@angular/compiler-cli": "^22.0.0",
|
"@angular/compiler-cli": "22.0.5",
|
||||||
"@angular/localize": "^22.0.4",
|
"@angular/localize": "22.0.5",
|
||||||
"@angular/platform-browser-dynamic": "^22.0.0",
|
"@angular/platform-browser-dynamic": "22.0.5",
|
||||||
"@compodoc/compodoc": "^1.2.1",
|
"@compodoc/compodoc": "^1.2.1",
|
||||||
"@playwright/test": "^1.61.1",
|
"@playwright/test": "^1.61.1",
|
||||||
"@storybook/addon-a11y": "^10.4.6",
|
"@storybook/addon-a11y": "^10.4.6",
|
||||||
|
|||||||
+14
-14
@@ -42,24 +42,24 @@
|
|||||||
"private": true,
|
"private": true,
|
||||||
"packageManager": "npm@11.12.1",
|
"packageManager": "npm@11.12.1",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@angular/common": "^22.0.0",
|
"@angular/common": "22.0.5",
|
||||||
"@angular/compiler": "^22.0.0",
|
"@angular/compiler": "22.0.5",
|
||||||
"@angular/core": "^22.0.0",
|
"@angular/core": "22.0.5",
|
||||||
"@angular/forms": "^22.0.0",
|
"@angular/forms": "22.0.5",
|
||||||
"@angular/platform-browser": "^22.0.0",
|
"@angular/platform-browser": "22.0.5",
|
||||||
"@angular/router": "^22.0.0",
|
"@angular/router": "22.0.5",
|
||||||
"rxjs": "~7.8.0",
|
"rxjs": "~7.8.0",
|
||||||
"tslib": "^2.3.0"
|
"tslib": "^2.3.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@angular-devkit/architect": "^0.2200.0",
|
"@angular-devkit/architect": "0.2200.5",
|
||||||
"@angular-devkit/build-angular": "^22.0.0",
|
"@angular-devkit/build-angular": "22.0.5",
|
||||||
"@angular-devkit/core": "^22.0.0",
|
"@angular-devkit/core": "22.0.5",
|
||||||
"@angular/build": "^22.0.4",
|
"@angular/build": "22.0.5",
|
||||||
"@angular/cli": "^22.0.4",
|
"@angular/cli": "22.0.5",
|
||||||
"@angular/compiler-cli": "^22.0.0",
|
"@angular/compiler-cli": "22.0.5",
|
||||||
"@angular/localize": "^22.0.4",
|
"@angular/localize": "22.0.5",
|
||||||
"@angular/platform-browser-dynamic": "^22.0.0",
|
"@angular/platform-browser-dynamic": "22.0.5",
|
||||||
"@compodoc/compodoc": "^1.2.1",
|
"@compodoc/compodoc": "^1.2.1",
|
||||||
"@playwright/test": "^1.61.1",
|
"@playwright/test": "^1.61.1",
|
||||||
"@storybook/addon-a11y": "^10.4.6",
|
"@storybook/addon-a11y": "^10.4.6",
|
||||||
|
|||||||
+1
-1
@@ -27,7 +27,7 @@ step "check:tokens"; npm run check:tokens
|
|||||||
step "check:seam"; npm run check:seam
|
step "check:seam"; npm run check:seam
|
||||||
step "test (vitest + coverage)"; npm run test:coverage
|
step "test (vitest + coverage)"; npm run test:coverage
|
||||||
step "build --localize (nl+en)"; npx ng build ssp --localize; npx ng build behandelportal --localize
|
step "build --localize (nl+en)"; npx ng build ssp --localize; npx ng build behandelportal --localize
|
||||||
step "npm audit (shipped deps)"; npm audit --omit=dev
|
step "npm audit (shipped deps)"; npm audit --omit=dev --audit-level=high
|
||||||
step "backend format + tests"; ( cd backend && dotnet format BigRegister.slnx --verify-no-changes && dotnet test BigRegister.slnx --filter "Category!=Integration" )
|
step "backend format + tests"; ( cd backend && dotnet format BigRegister.slnx --verify-no-changes && dotnet test BigRegister.slnx --filter "Category!=Integration" )
|
||||||
step "backend dependency audit"; ./scripts/dotnet-audit.sh
|
step "backend dependency audit"; ./scripts/dotnet-audit.sh
|
||||||
step "showcase snippets drift"; npm run gen:snippets; git diff --exit-code apps/ssp/src/app/showcase/snippets.generated.ts
|
step "showcase snippets drift"; npm run gen:snippets; git diff --exit-code apps/ssp/src/app/showcase/snippets.generated.ts
|
||||||
|
|||||||
Reference in New Issue
Block a user