Rough Stack treats dependency maintenance as part of its security posture.
- Runtime and development dependencies must be declared in
package.jsonand resolved reproducibly bypackage-lock.json. - Pull requests must use
npm ci; changes topackage.jsonmust include the corresponding lockfile update. - CI rejects high- and critical-severity advisories in production dependencies
with
npm run security:audit. - Maintainers review the full dependency tree with
npm run security:audit:all. Unpatched development-tool advisories remain visible without blocking a production release when they cannot affect the shipped application. - Automated dependency pull requests are enabled through Dependabot and still require the normal test and review gates.
- Exact transitive overrides are allowed only to remediate a published advisory or compatibility defect. Remove an override when the direct dependency resolves it upstream.
- New dependencies should be actively maintained, necessary for the feature, and compatible with the Apache-2.0 distribution. Copyleft or non-standard licenses require explicit maintainer review before merge.
Run these checks before a dependency release:
npm ci
npm run security:audit
npm run security:audit:all
npm ls --all
npm run typecheck
npm run lint
npm run test
npm run buildThe private package flag intentionally prevents accidental publication to
the npm registry; it does not restrict the source repository's Apache-2.0
license.