Skip to content

[finding] main's lockfile matches four advisories (proxy-addr 2.0.7 critical, source-map-js 1.2.1 high, sprintf-js 1.1.3 no fix, katex 0.16.47): the scheduled OSV scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21945

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (b). main is red on its own scheduled run. Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) because PR #21930 (#21880) inherits the red. ⛔ Not graded or routed here. ⛔ Not a claim. ⛔ No dependency is changed by this lane.

What is measured

  • The red runs. validate-deps.yml's scheduled run on main failed at "Audit dependencies for known vulnerabilities (OSV-Scanner)": run 37407261685 at 9e33ee7c59, started 2026-10-06T03:04Z.
  • The advisory set. The job log and api.osv.dev are both refused by this container's egress, so the OSV run's own advisory list is NOT MEASURED. The seat read the same lockfile instead: every name@version in main's pnpm-lock.yaml packages: section, 1243 names, sent to npm's bulk advisory endpoint (POST registry.npmjs.org/-/npm/v1/security/advisories/bulk), which answered 200. It matched four advisories, and osv-scanner.toml exempts none of them:
package @ locked advisory severity vulnerable fix pulled in by (declared range)
proxy-addr 2.0.7 GHSA-jqcg-44mw-7w3h (IP spoofing via an IPv4-mapped IPv6 trust subnet) critical >=1.1.0 <2.0.8 2.0.8, published 2026-09-15 express 5.2.1 (^2.0.7)
source-map-js 1.2.1 GHSA-68fv-2mgg-jv7q (event-loop DoS through indexed source-map section offsets) high >=1.0.0 <1.2.2 1.2.2, published 2026-09-30 postcss 8.5.28, @tailwindcss/node 4.3.3, css-tree 3.2.1, magicast 0.5.3 (all ^1.2.1)
sprintf-js 1.1.3 GHSA-hp3w-g68c-fv3c (DoS through unbounded precision specifiers) moderate <=1.1.3 none: 1.1.3 is the latest published version tedious 18.6.2, fengari 0.1.5 (both ^1.1.3)
katex 0.16.47 GHSA-238p-pmpm-9mq7 (existing prototype pollution can bypass trust restrictions) low >=0.11.0 <0.18.2 0.18.2+ (latest 0.19.0) mermaid 11.16.1 (^0.16.45); latest mermaid 12.1.0 still declares ^0.16.47

What each needs (direction only; the owning lane decides)

Reader who acts

Triage grades it and routes it to the lane that owns the root lockfile and osv-scanner.toml. Validate Package Dependencies is not one of main's required contexts (rules read: TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance, Lint & Repo Gates, Governed Surface Queue Guard). So this does not block a landing; it is a red that every package.json-touching PR inherits.

Dedupe: MCP search_issues, repo-scoped: 「OSV-Scanner red on main validate dependencies advisory proxy-addr katex source-map-js sprintf-js」. The seat ran it before filing: #21055, #20769, #20705, #20561 and #18930 are the same class and all closed, and none is this set. A repo-scoped scan of issues and open PRs updated since 2026-10-05T18:00Z naming any of the four packages found none.

Dedupe words: OSV red main proxy-addr GHSA-jqcg-44mw-7w3h · source-map-js GHSA-68fv-2mgg-jv7q · sprintf-js GHSA-hp3w-g68c-fv3c no fix · katex GHSA-238p-pmpm-9mq7 mermaid


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxpriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions