Which audit-level threshold prevents CI failure for low-severity vulnerabilities?
When integrating npm audit into a Continuous Integration (CI) pipeline, the goal is to block builds based on critical security risks while ignoring noise from low-impact vulnerabilities that do not affect the specific application runtime. The --audit-level flag is used to filter the reporting threshold. However, there is uncertainty regarding how the exit co