Auditor
No shipping locked dependency carries a known CRITICAL or HIGH advisory (OSV snapshot of the run date); the report states the advisory severity and ours.
1.1.0: the severity of an advisory stays the SOURCE's and the report now publishes BOTH (`source <SEVERITY>` of OSV/GHSA, where moderate is read as medium, and `ours <severity>`), with one declared criterion of our own: a dependency pinned only for development in every route drops exactly one step (critical→high, high→medium), because it does not reach the running artefact; a severity is never raised, and an advisory the snapshot could not grade is reported as info with `source UNKNOWN` instead of being dropped. Three counting and identity fixes measured over a real attestation whose own `npm audit` was clean: (a) ONE finding per package and advisory, listing every affected version, the lockfiles and the number of lockfile entries — the same advisory over three co-existing versions of one package was three findings; (b) only REGISTRY entries are queried: a lockfile key with no `node_modules/` segment is a local directory (a workspace, a `file:`/`link:` entry), never the public package of the same name, so a workspace called `next` is no longer audited as npm `next@1.0.0`, and an npm alias is queried under its registry name; (c) every finding CITES THE LOCKFILE that pins the package, which until 1.0.2 was `null`. Also npm lockfileVersion 1 is parsed (`dependencies` tree): a v1 lockfile used to yield zero packages and PASS without looking at a single dependency. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative.))
| for (const pkg of registryPackages) { // never a workspace or file: entry |
| for (const a of await ctx.advisories.lookup(pkg)) { // OSV snapshot of the run date |
| const source = sourceSeverity(a); // the advisory's own grade, moderate = medium |
| const severity = devOnly(pkg) ? DEMOTED[source] : source; // our only departure, published |
| group(pkg.name, a.id).versions.add(pkg.version); // one finding per package + advisory |
| } |
| } |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.