name: Dependency Audit

on:
  push:
    branches: [main]
    paths:
      - "package.json"
      - "package-lock.json"
      - ".github/workflows/dependency-audit.yml"
  pull_request:
    paths:
      - "package.json"
      - "package-lock.json"
      - ".github/workflows/dependency-audit.yml"
  schedule:
    - cron: "0 9 * * 1"
  workflow_dispatch:

concurrency:
  group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
  cancel-in-progress: true

permissions:
  contents: read

env:
  NPM_CONFIG_FUND: "false"

jobs:
  npm-production-audit:
    name: NPM Production Dependency Audit
    runs-on: ubuntu-latest
    timeout-minutes: 10
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
        with:
          persist-credentials: false

      - name: Use Node.js 22.x
        uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
        with:
          node-version: 22.x
          cache: npm

      - name: Audit production dependency tree
        run: npm audit --omit=dev --audit-level=moderate
