You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* Added npm audit and license scanner to ci
* revert changes to standard
* fix reloading from dependency cache
* fix the cache restore in circle config
Copy file name to clipboardExpand all lines: README.md
+17Lines changed: 17 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -168,3 +168,20 @@ The scheduler coordinates the Action Object that requires to be dispatched. It w
168
168
[Notifier flow](docs/images/6.png)
169
169
170
170
Email notifier service is a separate app, that observes the same topic for messages with field *from* = `SYSTEM`. Its code is available in the [email-notifier](https://github.com/mojaloop/email-notifier) repository.
171
+
172
+
173
+
## Auditing Dependencies
174
+
175
+
We use `npm-audit-resolver` along with `npm audit` to check dependencies for vulnerabilities, and keep track of resolved dependencies with an `audit-resolv.json` file.
176
+
177
+
To start a new resolution process, run:
178
+
```bash
179
+
npm run audit:resolve
180
+
```
181
+
182
+
You can then check to see if the CI will pass based on the current dependencies with:
183
+
```bash
184
+
npm run audit:check
185
+
```
186
+
187
+
And commit the changed `audit-resolv.json` to ensure that CircleCI will build correctly.
0 commit comments