Fix audit errors + split out audit to a separate workflow#397
Merged
zastrowm merged 1 commit intostrands-agents:mainfrom Jan 13, 2026
Merged
Fix audit errors + split out audit to a separate workflow#397zastrowm merged 1 commit intostrands-agents:mainfrom
zastrowm merged 1 commit intostrands-agents:mainfrom
Conversation
Ran npm audit fix and split out auditing to a separate workflow NPM audit is blocking PRs & test statuses because it's done as part of running the tests. Instead do it as a separate workflow, which also cuts down on redundant checks since it's only done once instead of per OS/node-version
Unshure
approved these changes
Jan 13, 2026
Member
Unshure
left a comment
There was a problem hiding this comment.
Thanks for fixing this! Something I have been thinking about - Should we block prs if the audit check fails? I guess we should because if the pr brings in new dependencies, we should check if they pass our audit check.
Member
Author
I'd rather keep it optional as I don't want all PRs to start failing because main has a dependency failing For new dependencies, I think we can use the npm run audit as a signal IMHO |
7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Ran
npm audit fixto update dependencies and then split out auditing to a separate workflowNPM audit is blocking PRs & test statuses because it's done as part of running the tests. Instead do it as a separate workflow, which also cuts down on redundant checks since it's only done once instead of per OS/node-version (which don't matter because
npm run auditis OS-independentAlso needed to add an
ascast to fix an MCP issue - this is now issue #398Type of Change
Bug fix
Testing
How have you tested the change?
npm run checkChecklist
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.