Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
audit: env selection for report by larsgw · Pull Request #125 · npm/cli · GitHub
Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' audit: env selection for report by larsgw · Pull Request #125 · npm/cli · GitHub
Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' audit: env selection for report by larsgw · Pull Request #125 · npm/cli · GitHub
Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' audit: env selection for report by larsgw · Pull Request #125 · npm/cli · GitHub
Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' audit: env selection for report by larsgw · Pull Request #125 · npm/cli · GitHub
Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' audit: env selection for report by larsgw · Pull Request #125 · npm/cli · GitHub
Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); audit: env selection for report by larsgw · Pull Request #125 · npm/cli · GitHub
Skip to content

audit: env selection for report - #125

Closed
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13
Closed

audit: env selection for report#125
larsgw wants to merge 2 commits into
npm:release-nextfrom
larsgw:patch-13

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Select dependency environments with --only, --also and --production for
reports as well, instead of just for audit fix. Still reports the
filtered advisories, but changes the exit code (as is done with
advisories below --audit-level). Tests need updating due to the new way
of counting vulnerabilities.

See https://npm.community/t/3959

Select dependency environments with --only, --also and --production for reports as well, instead of just for audit fix. Still reports the filtered advisories, but changes the exit code (as is done with advisories below --audit-level). Tests need updating due to the new way of counting vulnerabilities.
See https://npm.community/t/3959
@larsgw
larsgw requested a review from a team as a code ownerDecember 17, 2018 20:56
@sneakypete81

Copy link
Copy Markdown

Thanks very much for doing this.

Still reports the filtered advisories

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@larsgw

larsgw commented Dec 17, 2018

Copy link
Copy Markdown
ContributorAuthor

Maybe I've misunderstood, but if I run npm audit --only=prod I wouldn't expect to see any advisories from dev dependencies.

@sneakypete81 I know, but that requires either modifying the audit report, which could have unintended side effects, or changing all the reporters. Since --audit-level also reports advisories under the set severity (correct me if I'm wrong), this seemed like warranted behavior.

@mikecbrant

Copy link
Copy Markdown

Anxiously awaiting merge. Thanks, @larsgw

@zkatzkat added semver:minor new backwards-compatible feature needs-discussion labels Jan 7, 2019
@evilpacket

Copy link
Copy Markdown

I did a quick test of --audit-level and it worked as I would intend it to.

I would expect these flags to be passed along to the reporters and for them to act appropriately, such as @sneakypete81 suggests when I say --only=prod to not show advisories that pertain to dev dependencies.

Looks like npm audit help would also need some updating to represent the new flags but I'm not sure the standard that's been set forth by the cli team for these things.

@iarna

iarna commented Jan 8, 2019

Copy link
Copy Markdown
Contributor

As Adam suggests, docs should be added to doc/cli/npm-audit.md and doc/misc/npm-config.md

Reporter filters go in https://github.com/npm/npm-audit-report/pulls and should be PRed there (please add a note here when they are)

@larsgw

larsgw commented Jan 17, 2019

Copy link
Copy Markdown
ContributorAuthor

I added the docs. --audit-level doesn't filter the reports on my end (v6.5.0), should I add that as well as the env filters?

Details
$ npm ini -y
$ npm i underscore.string@3.3.4
$ npm audit
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
1
$ npm audit --audit-level high
=== npm audit security report === # Run npm install underscore.string@3.3.5 to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ underscore.string │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/745 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 moderate severity vulnerability in 3 scanned packages
run `npm audit fix` to fix 1 of them.
$ echo $?
0

@zkat
zkatforce-pushed the release-next branch 5 times, most recently from db63b89 to b09bc8cCompareJanuary 23, 2019 18:36
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 7, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/Baumeister that referenced this pull request Feb 8, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/cli-error-notifier that referenced this pull request Feb 11, 2019
The security script might come back when this is merged and released:
npm/cli#125
@ngraefngraef mentioned this pull request Feb 14, 2019
@perrosen

Copy link
Copy Markdown

Any movement on this? Is there something I can do to help speeding this up? This is one of my most wanted features for npm audit since launch. Seeing CI builds fail because of dev dependencies is becoming a real annoyance.

mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
…d and gone
The security check might come back when this is merged and released:
npm/cli#125
mischah added a commit to micromata/generator-baumeister that referenced this pull request Feb 18, 2019
The security script might come back when this is merged and released:
npm/cli#125
@IPWright83

Copy link
Copy Markdown

Are there updates on this at all? I've got builds failing on our pipeline (and similarly don't want to auto fix them during the build), but it's all because of jest dependencies - which really don't matter at runtime.

@lucasfevi

Copy link
Copy Markdown

@IPWright83 there is now a production flag for npm audit on npm version v6.10+. Check the release notes: https://github.com/npm/cli/releases/tag/v6.10.0

@darcyclarkedarcyclarke added the Priority Backlog a "backlogged" item that will be tracked in a Project Board label Mar 10, 2020
@SoerenHenning

Copy link
Copy Markdown

Even though the --production flag is a nice improvement, we could only take full advantage of it if accompanied by a --development flag or so. Our use case is as follows: We would like to run npm audit as part of our build pipeline for both production and development dependencies. However, the build process should only fail for vulnerabilities in production. For vulnerabilities in dev dependencies, only a warning should be generated.

@darcyclarkedarcyclarke added Release 6.x work is associated with a specific npm 6 release and removed Priority Backlog a "backlogged" item that will be tracked in a Project Board labels Oct 1, 2020
@darcyclarkedarcyclarke modified the milestone: OSS - Sprint 17Oct 5, 2020
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
* feat: add Application Default Credentials (ADC) support (npm#103)
Extends the credential chain in get_token() to include ADC as a 4th source:
1. GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE env var
2. Encrypted credentials (~/.config/gws/credentials.enc)
3. Plaintext credentials (~/.config/gws/credentials.json)
4. ADC — GOOGLE_APPLICATION_CREDENTIALS env var, then
~/.config/gcloud/application_default_credentials.json
Both authorized_user and service_account ADC formats are detected via the
'type' field and parsed accordingly. This means users can authenticate with:
gcloud auth application-default login --client-id-file=client_secret.json
and gws will automatically pick up those credentials.
Closesnpm#103
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(auth): address review feedback on ADC support
- Extract duplicated JSON credential parsing into parse_credential_file()
helper to reduce duplication between GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE
and ADC code paths; uses serde_json::from_value to avoid second string parse
- Fix well-known ADC path on macOS: dirs::config_dir() returns
~/Library/Application Support on macOS, not ~/.config; use
dirs::home_dir().join('.config/gcloud/...') instead
- Hard-error when GOOGLE_APPLICATION_CREDENTIALS points to a missing file
(was: silently fall through to 'No credentials found')
- Add test_load_credentials_adc_env_var_service_account covering service
account credentials loaded via GOOGLE_APPLICATION_CREDENTIALS
- Remove unnecessary unsafe blocks from env var tests (set_var/remove_var
are not unsafe functions; thread safety is already handled by serial_test)
- Update changeset to include GOOGLE_WORKSPACE_CLI_TOKEN at top of lookup
order and clarify ADC fallback behaviour
Addresses review feedback from jpoehnelt on npm#125.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 3, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 15, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 9, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.xwork is associated with a specific npm 6 releasesemver:minornew backwards-compatible feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

17 participants

@larsgw@sneakypete81@mikecbrant@evilpacket@iarna@perrosen@slinkardbrandon@aeschright@zkat@linzhaoken@rahulbreddy@MNF@IPWright83@lucasfevi@SoerenHenning@isaacs@darcyclarke