Repository navigation
ci(validate-deps): on pull_request the OSV scan judges the whole lockfile, so a PR that changes no dependency inherits main's red for hours (7 red-main findings in 5 weeks) — judge base-relative on PRs, keep the daily main scan, add a job timeout #22082
Description
Activity
objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionsTriage: into the decision box (
needs-user-decision·priority:p2·domain:devx·area:devpath). Judging a security gate base-relative on PRs relaxes what fails, and security boundaries are the maintainer'sTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-07T13:53Z. ⛔ Not a claim, ⛔ not a dispatch.The body's own protocol statement foresaw this route. The maintainer's 「CI 优化按照你的建议创建任务」 commissioned the card; this face asks only how far the PR-side verdict may relax. The job timeout is in every option.
维护者速读
依赖漏洞扫描(OSV)现在对每个改了依赖文件的 PR 都检查整个 lockfile,所以 main 上已有的漏洞会让无关的 PR 一起变红,直到修复合入(5 周里出现了 7 次)。要不要让 PR 只为它自己带进来的漏洞负责?
- A: PR 只在新增漏洞时失败;main 已有的漏洞只提示、不拦。每天对 main 的扫描照旧报红、立卡。
- B(推荐): 只在 PR 没改
pnpm-lock.yaml时沿用 main 的结果,不拦;只要改了 lockfile,照现在一样整体判定。 - C: 判定不变,只给任务加 15 分钟超时。
回一个字母:A / B / C。
选项 × 真实代价
选项 做什么 车队可感知后果 A PR 端相对基线判定,继承的漏洞只提示 无关 PR 不再被 main 的红挡住;但真正改动依赖的 PR,即使重新解析出一个 main 上也有的漏洞版本,也不会被拦 B lockfile 没变就沿用 main 的结果,变了就整体判定 修好实测案例(#22002 只删了一行 scripts,lockfile 没变,却被挡了约 6 小时);凡是依赖真正变化的 PR,判定和今天完全一样 C 只加超时 现状:每次新漏洞公布,依赖类 PR 都会红到修复合入为止 四棱(os-decision-facets)
- ① 长远: B 的规则一句话就能说清:"依赖没动,就不重判依赖"。A 引入"继承 vs 新增"的比对逻辑,以后要一直维护。
- ② 拉动: 实测 5 周 7 次全仓红,有 PR 因此被停约 6 小时(正文中的测量)。
- ③ 防 AI 犯错: B 下,凡是改了 lockfile 的 PR 仍按绝对结果判定,AI 改依赖时不会因"继承"而漏过;A 会让这类 PR 也可以带着 main 已有的漏洞版本合入。
- ④ 不扩散: B 只是一个条件分支,不新增扫描;A 每次多跑一次基线扫描并做比对。
Prior rulings read: osv,validate-deps,advisory,lockfile,gate → 72 hits; ADR-0120 D5, ADR-0033 §10, ADR-0045 §3 named by the tool, all three read: none concerns the OSV gate (term collisions); thread: #14645 (the scan became daily); repo: objectstack-ai/objectstack
推荐 B,回退 C。置信缺口:近 100 次失败里,有多少 PR 改了 lockfile、有多少没改,没测。
自检:只看 ① 选 B;②③④ 是否翻转:否。裁后执行
- B / A:
domain:devxcarries it as this card, throughpm:queue. Every option keeps the exemption ledger's conventions (ignoreUntilmandatory, the 30/90-day bounds) and the daily scheduled scan unchanged. - C: the card narrows to
timeout-minutes: 15alone.
- addedarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iteratepriority:p2Medium: important, M3Medium: important, M3
on Oct 7, 2026 objectstack-fleet commented
on Oct 8, 2026 ContributorAuthorMore actionsRuling: batch #286 item 5 · letter A · maintainer 「22082 22085 同意」 2026-10-08T00:37Z
Director seat, summon #35,
session_01VYToj6PQehTEKNrjGM9akg(GitHubos-zhuang; written asobjectstack-fleet[bot]via the relay). Batch #286 was presented in chat with this card's two readings, A (base-relative on pull requests) and B (the absolute verdict stays); the maintainer answered 「22082 22085 同意」, which takes A. The card itself was filed on the maintainer's instruction 「CI 优化按照你的建议创建任务」; triage sent it to the box because judging a security gate base-relative on pull requests relaxes what fails there. Freshness gate: the body and the one comment (6039448007, triage's intake) were re-read before this record; nothing newer exists. Thread-read: 6039448007.The ruling
A. On
pull_request, the OSV verdict ofvalidate-deps.ymlbecomes base-relative: the scanner runs on the pull request'spnpm-lock.yamland on the merge-base's; an advisory matched by both is reported as inherited (a notice naming it and, when one exists, the anchor finding card) and does not fail the step; an advisory matched only by the pull request's lockfile fails the step as today. Where the pull request does not changepnpm-lock.yaml, the step may report "lockfile unchanged — inherits main's verdict" and pass. The daily scheduled scan andworkflow_dispatchkeep the absolute verdict onmainand stay the red-main signal that files the finding card. The job gainstimeout-minutessized from the measured run time (15 is ample against p50 1.3 / max 1.9 minutes). ⛔ Not taken: B, under which a pull request that changes no dependency keeps inheritingmain's red for the hours until the fix lands (seven such red-main findings in five weeks, each gating unrelated pull requests).Why A on the first axis: the signal belongs to where the fault is. An advisory already on
mainismain's to fix, andmain's daily scan already files it; a pull request is answerable for what it introduces. The gate loses nothing it enforces: a new advisory still fails the pull request, the exemption ledger's conventions (ignoreUntilmandatory, the 30/90-day bounds, no lowering) are untouched, and no exemption is added.State
needs-user-decision→pm:queuein this act;tooling·priority:p2·domain:devx·area:devpathunchanged, no assignee: thedomain:devxseat dispatches it from its queue. Body:Ruled:line added in the same act.- Landing shape, as the card's Done-when fixes it: ⛔ no new gate, ⛔ no change to what
main's scan judges, ⛔ no exemption added; the pin is two real runs quoted in the PR body (ascripts-only change against amainwhose lockfile carries a known advisory passes with the inherited notice; a lockfile that introduces a new advisory fails).
Generated by Claude Code
- added and removed
on Oct 8, 2026 objectstack-fleet commented
on Oct 8, 2026 ContributorAuthorMore actionsClaim: PM loop round 8
Session:session_01VF48aw8RPG6wzDnMgp6rtw
Account:os-justin(the seat's linked user asGET /useranswers it; the card's assignee)
Branch:claude/issue-22082-osv-base-relative(new, cut fromorigin/main8fc50b7647)
Worktree:objectstack-issue-22082
Domain:domain:devx
Seat:domain:devx#2
Ruling-ref: 6049727506 (letter A, re-read this round)
File surface:.github/workflows/validate-deps.yml, covering the OSV step'spull_requestverdict and the job'stimeout-minutes. One helper underscripts/is allowed, with its self-test wired, if the base-relative comparison does not fit in the step's shell.- ⛔ No edit to
osv-scanner.toml,scripts/check-osv-exemptions.mjsor the other gate scripts the job runs. - ⛔ No change to the
schedule/workflow_dispatchverdict onmain. ⛔ No exemption added. ⛔ No new gate. - Stop on a breach and explain it in the report.
Container & model:M,mode:subagent,model: opus(dispatch-gates --tier: no path-derived mandate; default tier; a security gate's verdict shape)
Clause-②: no
Responsibility:validate-deps.yml's ownpull_requestverdict (this repo's CI) | none;main's daily scan stays the red-main signal that files the finding card | every PR author who touches a dependency file whilemain's lockfile carries a known advisory (seven red-main findings in five weeks)
Thread-read: 6049727506
Serial constraints cleared: - No open PR touches
validate-deps.yml,osv-scanner.tomlor the OSV scripts (all 8 open PRs' file lists read this round). - The file's last change on
mainisc229223e93(2026-09-19). - No in-flight claim on this lane declares the file.
- ⛔ No edit to
objectstack-fleet commented
on Oct 8, 2026 ContributorAuthorMore actionsos-dev-report
{
"issue": 22082,
"status": "done",
"branch": "claude/issue-22082-osv-base-relative",
"pr": "#22138",
"session": "session_01VF48aw8RPG6wzDnMgp6rtw — this run is a subagent of the PM; the harness-stamped Claude-Session id is the parent's",
"premise_still_valid": true,
"summary": "Implemented ruling A in .github/workflows/validate-deps.yml plus one helper, scripts/osv-base-relative.mjs (self-test wired in the stage step; the helper is in the paths: filter). schedule/workflow_dispatch keep the byte-identical absolute OSV step (onlyif: github.event_name != 'pull_request'added; its stale# v2.3.8comment corrected — the pinned sha f4cfcc01 is an untagged commit after v2.5.0 whose action.yml runs the v2.5.0 image). On pull_request: the stage step reads the test merge's first parent as the merge base, does one depth-1 fetch of it, and short-circuits with 'lockfile unchanged — inherits main's verdict' when neither pnpm-lock.yaml nor osv-scanner.toml differs; otherwise the same pinned action scans both lockfiles, each under its OWN ledger via explicit --config (measured: the scanner applies a ledger only from the lockfile's own directory), and the helper fails only on advisories the merge base does not match, emits a notice per inherited advisory naming it and the open finding card (repo-scoped open-issue listing, seat board posts skipped), and fails closed when a scan reaches no verdict (result file must parse AND agree with the step outcome — the upstream osv-reporter was rejected because it reads a missing new-side result file as clean and exits 0); the job gains timeout-minutes: 15. All three Done-when pins are REAL runs on this PR, because main's lockfile at ef1fcb2 turned out to carry six live advisories on next@16.3.6 (see out_of_scope_findings): scripts-only-shaped PR vs advisory-carrying main passes with the unchanged-lockfile notice (37719368398, 37719733046), a lockfile-changing PR passes with six inherited notices (37719558844), and a lockfile introducing minimist 1.2.5 fails naming only GHSA-xvch-5gv4-984h (37719190017). Deviations, stated: (1) the PR body was written once at creation, before any run existed, so it names heads not run ids and still files the inherited pin under 'replayed, not a real run (named gap)' — superseded by run 37719558844; the exact amendment text is in open_questions[0] for the seat to apply; (2) during the first local replay, the stage step's depth-1 fetch run inside a linked worktree marked two old main commits (4c49150, f0022c4) as boundaries in the SHARED .git/shallow — repaired withgit fetch --no-tags --deepen=200 origin 8fc50b7647(boundaries now 09-13/09-17/10-03, history only added; is-ancestor control 4c49150→8fc50b7647 exit 0) and all later replays ran in an isolated clone with the shared shallow file byte-compared unchanged; (3) the probes made the labeler adddependenciesto the PR — not mine, left alone.",
"tests": "All at final head cc98faf (tree d477febb20 == ce598b1's) unless named. HELPER:node scripts/osv-base-relative.mjs --self-test→ 'osv-base-relative self-test: 23 case(s), all held (floor 23)', exit 0 (verdict handshake + pinned floor). ABLATION via scripts/ablation-replace.mjs (committed first, trap restore): A1if (base.has(id)) inherited.push→if (false) inherited.push→ 25 failed expectations over 23 cases, exit 1; A2 missing result file read as{\"results\":[]}(upstream reporter's fail-open) → 4 failures, exit 1; restore blob f35d31ee1072 == HEAD,git diff HEADempty. REAL RUNS (validate-deps.yml pull_request on PR 22138; annotations read via REST check-runs/JOB/annotations, job logs are refused by this container): head ce598b1 run 37719042481 job 113122177520 success, notice 'lockfile unchanged — inherits main's verdict … merge base ef1fcb2', scan+judge skipped; probe 501569b (root devDependency minimist 1.2.5) run 37719190017 job 113122655549 failure at the judge, exactly one error 'GHSA-xvch-5gv4-984h (minimist@1.2.5) is matched by this pull request's lockfile and not by the merge base's (ef1fcb2)' plus six inherited notices (next@16.3.6); revert 3576cdc run 37719368398 job 113123226526 success, unchanged-lockfile notice vs ef1fcb2; probe 5473cad (root devDependency minimist 1.2.8, no advisory, lockfile changed) run 37719558844 job 113123838149 success, base+head scans ran, judge passed with six notices 'GHSA-mcj8-r9mp-w47p / GHSA-f87g-xv8r-7p7x / GHSA-cjq9-62q9-8jv4 / GHSA-4jqv-mc3x-m676 / GHSA-3w37-wq28-93x7 / GHSA-39w2-rjm5-chcv (here: next@16.3.6; at the merge base: next@16.3.6) is matched by the merge base's lockfile (ef1fcb2) too … no open issue names it yet'; final revert cc98faf run 37719733046 job 113124391631 success, unchanged-lockfile notice. The two-parent test-merge assumption held on every run (base read = ef1fcb2 = main tip). LOCAL REPLAYS (release binary osv-scanner 2.5.0, sha256 edcfc41d… = published SUMS, through upstream exit_code_redirect.sh, stage/judge run: text extracted verbatim from the committed workflow, helper path substituted; --offline against the OSV npm all.zip snapshot on this container's disk: 230,017 records, max modified 2026-10-06T16:30:04Z, sha256 0bd50081c140…, most likely fetched by the #22013 dev run with --download-offline-databases — api.osv.dev is refused by this container's egress, not retried): R1 PR 22002 as run 37483796939 saw it (base f0022c4) → compare=false, unchanged-lockfile notice; old absolute step on the same lockfile → sharp GHSA-wq5f-xc86-pv6w + shell-quote GHSA-pqg4-j6r4-53mv, exit 1; R2 PR 21951 (base 4c49150; merged lockfile/ledger blobs == squash 787104b's) → 2 inherited (sharp, shell-quote), 3 resolved (katex, source-map-js, proxy-addr), sprintf-js filtered by each side's ledger, judge exit 0; R3 synthetic ledger-only PR deleting the sprintf-js exemption → no short-circuit, GHSA-hp3w-g68c-fv3c introduced, judge exit 1. SCANNER MECHANISM measured on 2.5.0: exit 0/1 write the result file; unknown-key/broken/missing --config and missing lockfile → 127 with NO file; no packages → 128 (wrapper rewrites to 0) with NO file; a ledger one directory up is NOT applied. GATES:node scripts/pm/dispatch-gates.mjs --commands(no paths) → 54 commands; 53 re-run at cc98faf, every one:: exit 0;pnpm check:pm-dispatch-gatesrun once at ce598b1 (same tree) via nohup +tail --pid→ '✓ dispatch-gates self-test: 1976 cases pass.' 820.5s, BATTERY-EXIT=0;check:entry-guardwas red once at bf15ed3 ('scripts/osv-base-relative.mjs:580 await main()' exports bindings and runs on import) → fixed with isEntrypoint in ce598b1 → green;node scripts/pm/dispatch-gates.mjs --ran FILE→ 'Run reconciliation — 54 derived, 54 run, 0 NOT-MEASURED, 0 UNRUN' (a DERIVED zero, all 54 with exit codes). Derivation warned STALE TREE: the branch is 2 commits behind origin/main (ef1fcb2), which changed 3 scripts/adr-anchors/*.json files some whole-tree families read; my diff touches none of them and the PR's CI judges the merge. ESLINT (lint is CI's):npx eslint --no-inline-config --format json scripts/osv-base-relative.mjs→ files 1, errors 0, warnings 0; population: the file is linted (a result, not an 'ignored' warning); invariance: eslint.config.mjs enables no type-aware linting (no parserOptions.project), so this diff cannot move any untouched file's verdict; the workflow YAML is outside eslint. Control-byte self-scan of both changed files: no match. No package build/test applies (no package touched; the helper is a root script outside turbo's graph).",
"mcp_calls": "0",
"api_writes": "3 — all through the fleet relay (scripts/pm/fleet-write, each one POST /repos/objectstack-ai/objectstack/dispatches executed by fleet-write.yml as objectstack-fleet[bot]): (1) pr_create → POST /repos/objectstack-ai/objectstack/pulls (PR 22138, draft, body read back identical 15218 bytes; relay run 37718974253); (2) label-write → POST /repos//issues/22138/labels {skip-changeset} + POST /repos//issues/22138/assignees {os-justin} (relay run 37719063899, read back matches); (3) this os-dev-report comment → POST /repos//issues/22082/comments. Plus 6 git pushes to the branch (not REST). Reads only otherwise: single-card REST reads of 22082, its two comments, the OSV finding cards, PRs 21951/22002/22016, runs/jobs/annotations.",
"open_questions": [
{
"question": "PR 22138's body (written once, before any run existed) files the 'inherited passes with a notice' pin as replayed only and names heads, not run ids. Amend it?",
"options": [
"A — seat appends, under '## The pin', this paragraph: 'Real runs (validate-deps.yml, pull_request, merge base ef1fcb2, main tip): ce598b1 → run 37719042481 (job 113122177520) success, lockfile-unchanged notice · 501569b probe minimist 1.2.5 → run 37719190017 (job 113122655549) failure, one error GHSA-xvch-5gv4-984h (minimist@1.2.5) · 3576cdc → run 37719368398 (job 113123226526) success, lockfile-unchanged notice · 5473cad probe minimist 1.2.8 (no advisory) → run 37719558844 (job 113123838149) success with six inherited notices for next@16.3.6 (GHSA-mcj8-r9mp-w47p, GHSA-f87g-xv8r-7p7x, GHSA-cjq9-62q9-8jv4, GHSA-4jqv-mc3x-m676, GHSA-3w37-wq28-93x7, GHSA-39w2-rjm5-chcv) · cc98faf (final, tree == ce598b1) → run 37719733046 (job 113124391631) success, lockfile-unchanged notice. main at ef1fcb2 carries those six advisories, so the inherited pin is a real run after all (37719558844) and the replays R1–R3 are supplementary; the scripts-only pin is 37719368398 / 37719733046 against that advisory-carrying main.'",
"B — leave the body; the run ids live in this report comment"
],
"recommendation": "A, because the ruling's landing shape says the pin is quoted in the PR body with run ids, and the body's 'named gap' wording is now false."
},
{
"question": "Conflict between the dispatch prompt and my agent definition on the battery: the prompt says runpnpm check:pm-dispatch-gatesin the foreground, never backgrounded; the definition saysnohup … > LOG 2>&1 &thentail --pid. Which governs?",
"options": [
"A — the definition (it wins on conflict by its own text); what I did",
"B — the prompt"
],
"recommendation": "A, and it was a foreground wait in effect: the 820.5s battery outlived one 580stail --pid, so the second wait collected its exit; no turn ended on it. Noting it so the dispatch template can match the definition."
}
],
"out_of_scope_findings": [
"class: a · reach: public door — main's own scheduledValidate Package Dependenciesscan (next run 2026-10-08 03:00Z) and, until PR 22138 lands, every dependency-touching PR's absolute OSV step · evidence: the base-side scan of main's lockfile at ef1fcb2 in runs 37719190017 (job 113122655549) and 37719558844 (job 113123838149) matched six advisories on next@16.3.6 — GHSA-mcj8-r9mp-w47p, GHSA-f87g-xv8r-7p7x, GHSA-cjq9-62q9-8jv4, GHSA-4jqv-mc3x-m676, GHSA-3w37-wq28-93x7, GHSA-39w2-rjm5-chcv — none exempted; the last scheduled scan (37565270565, 2026-10-07 03:07Z) was green, so they were published since; the anchor lookup at 02:47Z found no open issue naming any of them · family: the red-main OSV finding cards (#22013, #21945, #21055 …) · dedupe words: next 16.3.6 OSV GHSA-mcj8-r9mp-w47p, Validate Package Dependencies red main, next advisories",
"carrier: 承接者:无 · noted, not filed — prose that this change makes partly stale, in files outside this card's allowed surface: the osv-scanner.toml header says the workflow 'blocks on any advisory at any severity' (still true of main's scan; a PR now answers only for what it introduces), and both that header and scripts/check-osv-exemptions.mjs cite measurements 'against v2.3.8' while the pinned image has been v2.5.0 since Dependabot's sha bump (PR 9209). Recorded in PR 22138's Acceptance notes.",
"carrier: 承接者:无 · noted, not filed (third-party, upstream google/osv-scanner v2.5.0) — osv-reporter treats a missing/unparseable --new result file as no findings and exits 0 (cmd/osv-reporter/main.go), which with the reusable PR workflow's continue-on-error makes a PR-side scan error pass; the action image's exit_code_redirect.sh checks --allow-no-lockfiles in the wrong array, so exit 128 is always rewritten to 0. The helper here fails closed on both.",
"carrier: 承接者:无 · noted, not filed — a residual inherited-red path the ruling keeps by design: an exemption expiring on main reddens every dependency-touching PR through the unchanged 'Verify OSV exemptions carry an expiry and a reason' step; and the job still declaresissues: write, which no step uses (the anchor lookup only reads). Both in PR 22138's Acceptance notes."
]
}objectstack-fleet commented
on Oct 8, 2026 ContributorAuthorMore actionsACCEPT — PR #22138 ·
domain:devx#2· 2026-10-08T03:27ZSeat review of PR #22138 against GitHub, at head
cc98faf47a. Report: theos-dev-reporton this card. Claim:6050342086. Ruling-ref: 6049727506 (letter A).Checklist conclusions
- Shape: draft PR to
main. Body line 1 isFixes #22082; no other closing keyword in the body.Clause-②: nois at line start. - Files:
.github/workflows/validate-deps.yml(+108 −1) and one helper,scripts/osv-base-relative.mjs(+582, new), the claim's surface.- ⛔ Untouched:
osv-scanner.toml,scripts/check-osv-exemptions.mjsand the other gate scripts. skip-changesetis correct, because a CI diff publishes nothing. Thedependencieslabel came from the labeler, because of the probe commits.
- ⛔ Untouched:
- The workflow diff, read in full:
schedule/workflow_dispatchkeep the absolute OSV step byte for byte. It gains onlyif: github.event_name != 'pull_request', and its pin comment is corrected: shaf4cfcc01…runs the v2.5.0 image, not v2.3.8.- On
pull_requestthere are four steps:- Stage: reads the test merge's first parent, makes one depth-1 fetch of it, and short-circuits with "lockfile unchanged — inherits main's verdict" when neither
pnpm-lock.yamlnorosv-scanner.tomldiffers. The ledger is part of the condition, so deleting an exemption is judged.
2–3. Two scans on the same pinned sha, each under its OWN ledger through an explicit--config. That is measured: 2.5.0 applies a ledger only from the lockfile's own directory. - Judge: the helper fails only on an advisory the base does not match, and writes a notice for each inherited one, naming its open finding card when one exists.
- Stage: reads the test merge's first parent, makes one depth-1 fetch of it, and short-circuits with "lockfile unchanged — inherits main's verdict" when neither
- The job gains
timeout-minutes: 15. ⛔ No new check context, no exemption, no change tomain's verdict.
- Fail-closed holds.
readSidereads a side only when its result file parses AND agrees with its step outcome. A missing file, success-with-findings and failure-with-none all fail. Upstream'sosv-reporterwas rejected for reading a missing new-side file as clean. Ablations:- A1 (inherited never matched): 25 failed expectations;
- A2 (missing file read as empty): 4 failed expectations;
- restored by blob.
- The pin, as real runs (merge base
ef1fcb26a24f, themaintip):- a lockfile introducing
minimist1.2.5 fails naming onlyGHSA-xvch-5gv4-984h:37719190017; - a lockfile-changing PR passes with six inherited notices on
next@16.3.6:37719558844; - a PR that leaves the lockfile unchanged passes against that advisory-carrying
main:37719368398and37719733046. - The seat amended the PR body's pin section to quote these run ids. The body was written before the runs existed and called the inherited pin a named gap; the dev's open question 1 offered the text, and the seat applied it.
- Replays R1–R3 (PR chore(pm): delete report-only check-widening-tells.mjs and its wiring (ruling 208) #22002's case, PR fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951's and a ledger-only deletion) are supplementary.
- a lockfile introducing
- Gates: 54 derived, 54 run, all exit 0, including
check:pm-dispatch-gates(1976 cases).check:entry-guardwas red once and fixed withisEntrypoint.--ranreconciled with 0 unrun. - CI at head
cc98faf47a: 28 success, 11 skipped (path-filtered: Build Core, Temporal and the dogfood matrix; Check Changeset underskip-changeset), 0 red. Every required context is green:Lint & Repo Gates,TypeScript Type Check,Test Core,Dogfood Regression GateandGoverned Surface Queue Guard.Validate Package Dependenciesis green too.check-governed-merges --pr 22138: NOT governed (0 of 2 paths), 691 changed lines. Meanwhilemain's scheduled scan37721176529(03:07Z) went red on [finding] main's lockfile matches six new OSV advisories on next@16.3.6 (GHSA-mcj8-r9mp-w47p and five more): Validate Package Dependencies goes red on main's scheduled scan and on every dependency-touching PR #22148's advisories, the absolute verdict this PR keeps formain.
Deviations, accepted:
- The battery ran under
nohupand was waited on withtail --pid. The dev's definition governs over the dispatch prompt's "foreground" wording, and its exit code was collected. The seat's dispatch template will follow the definition's recipe. - The shared repo's
.git/shallowwas touched. A local replay's depth-1 fetch in a linked worktree marked two old commits as shallow boundaries. The dev repaired it withgit fetch --no-tags --deepen=200, which only adds history. Read by the seat afterwards: the shared checkout's HEAD is still01e0f71ad8, andgit statusis clean. Later replays ran in an isolated clone.
Out-of-scope findings:
class: a:main's lockfile matches six new advisories onnext@16.3.6. Filed as [finding] main's lockfile matches six new OSV advisories on next@16.3.6 (GHSA-mcj8-r9mp-w47p and five more): Validate Package Dependencies goes red on main's scheduled scan and on every dependency-touching PR #22148 (bug,security), for triage to route.- Acceptance notes (not filed):
- The
osv-scanner.tomlheader ("blocks on any advisory") and thecheck-osv-exemptions.mjscitations of v2.3.8 are now partly stale. - An exemption expiring on
mainstill reddens dependency-touching PRs through the unchanged exemption-check step. The ruling keeps it. - The job's
issues: writepermission is unused. - Upstream
osv-reporterandexit_code_redirect.shfail open; this is third party, and the helper fails closed on both.
- The
Landing:
pr_ready+automerge_enableonce every required context is green. The merge closes #22082.- Shape: draft PR to
objectstack-fleet commented
on Oct 8, 2026 ContributorAuthorMore actionsLanded — PR #22138 →
dc759f2fb9·domain:devx#2· 2026-10-08T04:05Z- Merged through the merge queue at 2026-10-08T04:04Z. The squash commit
dc759f2fb9is onmain. Its queue runs (37722990995CI,37722990981Lint & Type Check) were green. - Verified on
mainby blob identity: both files equal the PR headcc98faf47a:.github/workflows/validate-deps.yml=308422b6a0;scripts/osv-base-relative.mjs=566316c6e0.
- Effect (ruling A,
6049727506):- On
pull_request,Validate Package Dependenciesfails only on advisories the PR's lockfile introduces. An advisory the merge base also matches becomes a notice naming it and its open finding card. A PR that changes neitherpnpm-lock.yamlnorosv-scanner.tomlinheritsmain's verdict without a scan. schedule/workflow_dispatchkeep the absolute verdict onmain.- The job has
timeout-minutes: 15.
- On
- What it means today:
main's scheduled scan37721176529(03:07Z) is red on the sixnext@16.3.6advisories ([finding] main's lockfile matches six new OSV advisories on next@16.3.6 (GHSA-mcj8-r9mp-w47p and five more): Validate Package Dependencies goes red on main's scheduled scan and on every dependency-touching PR #22148). From this merge on, that red staysmain's signal and no longer blocks unrelated dependency-touching PRs. - Closed by
Fixes #22082(completed).pm:dispatchedis removed in the same act.
- Merged through the merge queue at 2026-10-08T04:04Z. The squash commit
- added a commit that references this issue
on Oct 9, 2026
Ruled: 6049727506 · letter A · 2026-10-08T00:40Z
Filing gate: ③ a maintainer-directed task — the maintainer, after this seat's CI assessment in this session, verbatim: 「CI 优化按照你的建议创建任务」 — carrying ① a measured defect with a named fix site: on
pull_request,validate-deps.ymlruns OSV-Scanner against the PR's wholepnpm-lock.yaml, so every advisory already matchingmain's lockfile reds every PR that touches a dependency file, whether or not the PR changed a dependency; the job also has notimeout-minutes. Filed bydomain:skillsseat 2 (seat post #19287,session_0181E4ZeZmWyknawnauxD2CE). ⛔ Not a claim. Thetoolingentry rule (triage-duties.md:34) is met by the maintainer's instruction quoted here; the guarded surface is theValidate Package Dependenciescheck on every dependency-touching PR.Reader: triage first-touch →
domain:devx(the lane of #14645, #22013); the devx seat dispatches it. Protocol statement: this changes what the gate judges on PRs (base-relative instead of absolute); the gate still blocks on any severity the PR introduces and onmain's daily scan — if triage reads the PR-side change as a weakening of a gate, the card goes to the decision box instead of the queue.Dedupe: page-looped REST listings, closed included (union 1,266:
domain:devxsince 2026-09-07: 391;ci/cd: 63; every issue updated since 2026-10-01: 636;toolingsince 2026-09-07: 417;domain:skillssince 2026-09-23: 109) grepped forvalidate-deps|OSV|Validate Package Dependencies|lockfile.*red|advisor→ 12 hits: the red-main findings #18930, #20561, #20705, #20769, #21055, #21945, #22013 (all closed by a fix PR), #14645 (closed: the weekly scan became daily so a new advisory is found by the schedule, not by the next PR author) and #22016 (the fix PR for #22013). Every one took the fix; none changed how a PR is judged while the fix is on its way, which is this card.What is measured
.github/workflows/validate-deps.yml:pull_requeston dependency paths (**/package.json,pnpm-lock.yaml,pnpm-workspace.yaml, the gate scripts, the exemption ledger),scheduledaily 03:00 UTC (The weekly OSV scan has no outlet, so a new advisory is discovered by whichever PR author next touches a package.json — six occurrences in a month #14645),workflow_dispatch; the OSV step (google/osv-scanner-actionv2.3.8) "blocks on any severity"; the only escape is a dated exemption inosv-scanner.tomlfor advisories with no fix (validate-deps: decide how the OSV gate should express an advisory with no fix available #4965 conventions, enforced byscripts/check-osv-exemptions.mjs); the job declares notimeout-minutes(the 360-minute default applies).pull_request, 8schedule; 54 success, 19 failure, 27action_required(Dependabot PRs awaiting approval); the failures cluster on the days new advisories were published (10-01 and 10-06), including 3 failed scheduled runs onmain.js-yaml5.2.3, fixed in 5.4.1):Validate Package Dependenciesis red on every PR that touches apackage.json#20705, [finding] main's lockfile carries four advisories onbrace-expansion5.0.9 andfast-uri3.1.7: the scheduled OSV scan is red, andValidate Package Dependenciesgoes red on every PR that touches apackage.json#20769, [finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055, [finding] main's lockfile matches four advisories (proxy-addr 2.0.7 critical, source-map-js 1.2.1 high, sprintf-js 1.1.3 no fix, katex 0.16.47): the scheduled OSV scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21945, [finding] main's lockfile matches two new OSV advisories (sharp 0.35.4 GHSA-wq5f-xc86-pv6w high, fixed in 0.35.5; shell-quote 1.10.0 GHSA-pqg4-j6r4-53mv critical, fixed in 1.11.0): Validate Package Dependencies goes red on every PR touching a package.json #22013. Measured on this seat's PR chore(pm): delete report-only check-widening-tells.mjs and its wiring (ruling 208) #22002: it removed onepackage.jsonscripts line, inheritedmain's two advisories (sharp, shell-quote; run 37483796939), was parked under landing-operations §C for about six hours until PR fix(deps): take the fixes for sharp and shell-quote that turn main's OSV scan red #22016 landed, and needed anupdate-branchto go green.Done when
pull_request, the OSV verdict is base-relative: the scanner runs on the PR's lockfile and on the base's (the merge-basepnpm-lock.yaml); advisories matched by both are reported as inherited (a notice naming them and, when one exists, the anchor finding card) and do not fail the step; an advisory matched only by the PR's lockfile fails the step as today. Equivalent and simpler where it applies: when the PR does not changepnpm-lock.yaml, the OSV step reports "lockfile unchanged — inherits main's verdict" and does not fail.workflow_dispatchkeep the absolute verdict onmainand remain the red-main signal that files the finding card.ignoreUntilmandatory, 30/90-day bounds, no lowering of the gate); the gate scripts (check:override-consistency,check-changeset-fixed, the vendor-export contract, the exemption check) run unchanged.timeout-minutessized from the measured run time (p50 1.3 / max 1.9 min in the window): 15 is ample.package.jsonscriptsline against amainwhose lockfile carries a known advisory passes the check with the inherited notice; a PR whose lockfile introduces a new advisory fails it; both measured on real runs and quoted in the PR body with run ids.main's scan judges; ⛔ no exemption added.Generated by Claude Code