feat(security): harden dependency governance

This commit is contained in:
xixu-me committed 2026-03-31 01:36:17 +08:00
1 parent 4153beb619
commit 9e24204f63
12 files changed
+808 -4587

No files matched your search

+38
View File
@@ -0,0 +1,38 @@
const test = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const projectRoot = path.resolve(__dirname, '..');
function read(relativePath) {
return fs.readFileSync(path.join(projectRoot, relativePath), 'utf8');
}
test('package.json exposes the security audit script and excludes removed cloud dependencies', () => {
const packageJson = JSON.parse(read('package.json'));
assert.equal(packageJson.scripts['security:audit'], 'node ./scripts/security-audit-report.cjs');
assert.match(packageJson.scripts['test:ci'], /tests\/security-governance\.test\.cjs/);
assert.ok(!('@google-cloud/translate' in packageJson.dependencies));
assert.ok(!('express' in packageJson.dependencies));
assert.ok(!('firebase-admin' in packageJson.dependencies));
assert.ok(!('firebase-functions' in packageJson.dependencies));
assert.ok(!('firebase-functions-test' in packageJson.devDependencies));
});
test('security governance workflow enforces npm audit policy and uploads reports', () => {
const workflow = read('.github/workflows/security-governance.yml');
assert.match(workflow, /name:\s+Security Governance/);
assert.match(workflow, /run:\s+npm run security:audit/);
assert.match(workflow, /actions\/upload-artifact@v4/);
assert.match(workflow, /cron:\s+'31 17 \* \* 1'/);
});
test('security baseline file is present and ready for future exceptions', () => {
const baseline = JSON.parse(read('security/npm-audit-baseline.json'));
assert.ok(Array.isArray(baseline.entries));
assert.equal(baseline.entries.length, 0);
});