Which audit-level threshold prevents CI failure for low-severity vulnerabilities?
25.5K reputation · 11 Oct 2020, 07:18 UTC
When integrating npm audit into a Continuous Integration (CI) pipeline, the goal is to block builds based on critical security risks while ignoring noise from low-impact vulnerabilities that do not affect the specific application runtime.
The --audit-level flag is used to filter the reporting threshold. However, there is uncertainty regarding how the exit codes behave when multiple severity levels are present in the dependency tree. If a project contains both 'low' and 'critical' vulnerabilities, it is necessary to ensure the pipeline only fails when the threshold is met or exceeded.
- Does setting
--audit-level=highsuppress the non-zero exit code for 'low' and 'moderate' vulnerabilities? - What is the expected behavior of the audit process when a vulnerability is identified in a nested dependency that cannot be resolved via
npm audit fix?