Skip to content

DO NOT MERGE: test security-audit-required gate (release branch)#23

Draft
chrisdp wants to merge 2 commits into
masterfrom
release/test-audit-gate
Draft

DO NOT MERGE: test security-audit-required gate (release branch)#23
chrisdp wants to merge 2 commits into
masterfrom
release/test-audit-gate

Conversation

@chrisdp
Copy link
Copy Markdown
Contributor

@chrisdp chrisdp commented May 20, 2026

Summary

Counterpart to #22. Verifies the security-audit-required gate blocks a release-branch PR when the audit fails.

Same deliberate revert: removes the serialize-javascript override to surface 2 high-severity advisories from mocha's transitive serialize-javascript.

Expected behavior

  • Security Audit / audit → ❌
  • Security Audit / security-audit-required → ❌ (head is release/*, so the gate propagates the audit result)
  • Merge blocked by the ruleset

If both checks fail and the merge button is disabled, the gate works. Close this PR without merging.

Deliberate revert to verify the security-audit-required gate behaves
correctly on non-release PRs. Do not merge.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant