(SECURITY) npm audit with gitlab CI

Viewed 687

How can I stop a build if the package.json contains a critical security flaw by doing npm audit in gitlab-ci.yml?

1 Answers

Create a job in your pipeline which runs ...

npm audit --audit-level=critical

Any critical vulnerabilities will cause it to exit with a non-zero exit code, which should then cause the job to fail and block further progress.

Related