Filing gate: ① a reproducible defect, class (b). main is red on its own scheduled run. Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) because PR #21930 (#21880) inherits the red. ⛔ Not graded or routed here. ⛔ Not a claim. ⛔ No dependency is changed by this lane.
What is measured
- The red runs.
validate-deps.yml's scheduled run on main failed at "Audit dependencies for known vulnerabilities (OSV-Scanner)": run 37407261685 at 9e33ee7c59, started 2026-10-06T03:04Z.
- The advisory set. The job log and
api.osv.dev are both refused by this container's egress, so the OSV run's own advisory list is NOT MEASURED. The seat read the same lockfile instead: every name@version in main's pnpm-lock.yaml packages: section, 1243 names, sent to npm's bulk advisory endpoint (POST registry.npmjs.org/-/npm/v1/security/advisories/bulk), which answered 200. It matched four advisories, and osv-scanner.toml exempts none of them:
| package @ locked |
advisory |
severity |
vulnerable |
fix |
pulled in by (declared range) |
proxy-addr 2.0.7 |
GHSA-jqcg-44mw-7w3h (IP spoofing via an IPv4-mapped IPv6 trust subnet) |
critical |
>=1.1.0 <2.0.8 |
2.0.8, published 2026-09-15 |
express 5.2.1 (^2.0.7) |
source-map-js 1.2.1 |
GHSA-68fv-2mgg-jv7q (event-loop DoS through indexed source-map section offsets) |
high |
>=1.0.0 <1.2.2 |
1.2.2, published 2026-09-30 |
postcss 8.5.28, @tailwindcss/node 4.3.3, css-tree 3.2.1, magicast 0.5.3 (all ^1.2.1) |
sprintf-js 1.1.3 |
GHSA-hp3w-g68c-fv3c (DoS through unbounded precision specifiers) |
moderate |
<=1.1.3 |
none: 1.1.3 is the latest published version |
tedious 18.6.2, fengari 0.1.5 (both ^1.1.3) |
katex 0.16.47 |
GHSA-238p-pmpm-9mq7 (existing prototype pollution can bypass trust restrictions) |
low |
>=0.11.0 <0.18.2 |
0.18.2+ (latest 0.19.0) |
mermaid 11.16.1 (^0.16.45); latest mermaid 12.1.0 still declares ^0.16.47 |
What each needs (direction only; the owning lane decides)
Reader who acts
Triage grades it and routes it to the lane that owns the root lockfile and osv-scanner.toml. Validate Package Dependencies is not one of main's required contexts (rules read: TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance, Lint & Repo Gates, Governed Surface Queue Guard). So this does not block a landing; it is a red that every package.json-touching PR inherits.
Dedupe: MCP search_issues, repo-scoped: 「OSV-Scanner red on main validate dependencies advisory proxy-addr katex source-map-js sprintf-js」. The seat ran it before filing: #21055, #20769, #20705, #20561 and #18930 are the same class and all closed, and none is this set. A repo-scoped scan of issues and open PRs updated since 2026-10-05T18:00Z naming any of the four packages found none.
Dedupe words: OSV red main proxy-addr GHSA-jqcg-44mw-7w3h · source-map-js GHSA-68fv-2mgg-jv7q · sprintf-js GHSA-hp3w-g68c-fv3c no fix · katex GHSA-238p-pmpm-9mq7 mermaid
Generated by Claude Code
Filing gate: ① a reproducible defect, class (b).
mainis red on its own scheduled run. Filed bydomain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi) because PR #21930 (#21880) inherits the red. ⛔ Not graded or routed here. ⛔ Not a claim. ⛔ No dependency is changed by this lane.What is measured
validate-deps.yml's scheduled run onmainfailed at "Audit dependencies for known vulnerabilities (OSV-Scanner)": run 37407261685 at9e33ee7c59, started 2026-10-06T03:04Z.packages:andsnapshots:lockfile sections are byte-identical tomain's (comment 6007522493).api.osv.devare both refused by this container's egress, so the OSV run's own advisory list is NOT MEASURED. The seat read the same lockfile instead: everyname@versioninmain'spnpm-lock.yamlpackages:section, 1243 names, sent to npm's bulk advisory endpoint (POST registry.npmjs.org/-/npm/v1/security/advisories/bulk), which answered 200. It matched four advisories, andosv-scanner.tomlexempts none of them:proxy-addr2.0.7>=1.1.0 <2.0.8express5.2.1 (^2.0.7)source-map-js1.2.1>=1.0.0 <1.2.2postcss8.5.28,@tailwindcss/node4.3.3,css-tree3.2.1,magicast0.5.3 (all^1.2.1)sprintf-js1.1.3<=1.1.3tedious18.6.2,fengari0.1.5 (both^1.1.3)katex0.16.47>=0.11.0 <0.18.2mermaid11.16.1 (^0.16.45); latestmermaid12.1.0 still declares^0.16.47What each needs (direction only; the owning lane decides)
proxy-addrandsource-map-js: each parent's declared range already admits the fix, so a lockfile refresh of those two resolves them. This is the same shape as [finding] main's lockfile carries GHSA-r3ph-w7gj-g6xm (js-yaml5.2.3, fixed in 5.4.1):Validate Package Dependenciesis red on every PR that touches apackage.json#20705 and [finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055.sprintf-js: no fixed version exists. Perosv-scanner.toml's header conventions (validate-deps: decide how the OSV gate should express an advisory with no fix available #4965), the only outlet is an[[IgnoredVulns]]entry withignoreUntiland areason, landed in its ownosv-exemption-labelled PR.katex: no publishedmermaidadmits a fixedkatex. It needs either apnpm.overridesentry (katex≥ 0.18.2, outsidemermaid's declared^0.16, socheck:override-consistencyjudges it) or an exemption. Its only consumer isapps/docs(mermaid^11.16.0).Reader who acts
Triage grades it and routes it to the lane that owns the root lockfile and
osv-scanner.toml.Validate Package Dependenciesis not one ofmain's required contexts (rules read: TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance, Lint & Repo Gates, Governed Surface Queue Guard). So this does not block a landing; it is a red that everypackage.json-touching PR inherits.Dedupe: MCP
search_issues, repo-scoped: 「OSV-Scanner red on main validate dependencies advisory proxy-addr katex source-map-js sprintf-js」. The seat ran it before filing: #21055, #20769, #20705, #20561 and #18930 are the same class and all closed, and none is this set. A repo-scoped scan of issues and open PRs updated since 2026-10-05T18:00Z naming any of the four packages found none.Dedupe words:
OSV red main proxy-addr GHSA-jqcg-44mw-7w3h·source-map-js GHSA-68fv-2mgg-jv7q·sprintf-js GHSA-hp3w-g68c-fv3c no fix·katex GHSA-238p-pmpm-9mq7 mermaidGenerated by Claude Code