Skip to content

ci(validate-deps): on pull_request the OSV scan judges the whole lockfile, so a PR that changes no dependency inherits main's red for hours (7 red-main findings in 5 weeks) — judge base-relative on PRs, keep the daily main scan, add a job timeout #22082

Description

@objectstack-fleet

Ruled: 6049727506 · letter A · 2026-10-08T00:40Z

Filing gate: ③ a maintainer-directed task — the maintainer, after this seat's CI assessment in this session, verbatim: 「CI 优化按照你的建议创建任务」 — carrying ① a measured defect with a named fix site: on pull_request, validate-deps.yml runs OSV-Scanner against the PR's whole pnpm-lock.yaml, so every advisory already matching main's lockfile reds every PR that touches a dependency file, whether or not the PR changed a dependency; the job also has no timeout-minutes. Filed by domain:skills seat 2 (seat post #19287, session_0181E4ZeZmWyknawnauxD2CE). ⛔ Not a claim. The tooling entry rule (triage-duties.md:34) is met by the maintainer's instruction quoted here; the guarded surface is the Validate Package Dependencies check on every dependency-touching PR.
Reader: triage first-touch → domain:devx (the lane of #14645, #22013); the devx seat dispatches it. Protocol statement: this changes what the gate judges on PRs (base-relative instead of absolute); the gate still blocks on any severity the PR introduces and on main's daily scan — if triage reads the PR-side change as a weakening of a gate, the card goes to the decision box instead of the queue.
Dedupe: page-looped REST listings, closed included (union 1,266: domain:devx since 2026-09-07: 391; ci/cd: 63; every issue updated since 2026-10-01: 636; tooling since 2026-09-07: 417; domain:skills since 2026-09-23: 109) grepped for validate-deps|OSV|Validate Package Dependencies|lockfile.*red|advisor → 12 hits: the red-main findings #18930, #20561, #20705, #20769, #21055, #21945, #22013 (all closed by a fix PR), #14645 (closed: the weekly scan became daily so a new advisory is found by the schedule, not by the next PR author) and #22016 (the fix PR for #22013). Every one took the fix; none changed how a PR is judged while the fix is on its way, which is this card.

What is measured

Done when

  • On pull_request, the OSV verdict is base-relative: the scanner runs on the PR's lockfile and on the base's (the merge-base pnpm-lock.yaml); advisories matched by both are reported as inherited (a notice naming them and, when one exists, the anchor finding card) and do not fail the step; an advisory matched only by the PR's lockfile fails the step as today. Equivalent and simpler where it applies: when the PR does not change pnpm-lock.yaml, the OSV step reports "lockfile unchanged — inherits main's verdict" and does not fail.
  • The daily scheduled scan and workflow_dispatch keep the absolute verdict on main and remain the red-main signal that files the finding card.
  • The exemption ledger's conventions are untouched (ignoreUntil mandatory, 30/90-day bounds, no lowering of the gate); the gate scripts (check:override-consistency, check-changeset-fixed, the vendor-export contract, the exemption check) run unchanged.
  • The job gets a timeout-minutes sized from the measured run time (p50 1.3 / max 1.9 min in the window): 15 is ample.
  • Pin: a PR that touches only a package.json scripts line against a main whose lockfile carries a known advisory passes the check with the inherited notice; a PR whose lockfile introduces a new advisory fails it; both measured on real runs and quoted in the PR body with run ids.
  • ⛔ No new gate; ⛔ no change to what main's scan judges; ⛔ no exemption added.

Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 7, 2026

    @objectstack-fleet
    ContributorAuthor

    Triage: into the decision box (needs-user-decision · priority:p2 · domain:devx · area:devpath). Judging a security gate base-relative on PRs relaxes what fails, and security boundaries are the maintainer's

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-07T13:53Z. ⛔ Not a claim, ⛔ not a dispatch.

    The body's own protocol statement foresaw this route. The maintainer's 「CI 优化按照你的建议创建任务」 commissioned the card; this face asks only how far the PR-side verdict may relax. The job timeout is in every option.

    维护者速读

    依赖漏洞扫描(OSV)现在对每个改了依赖文件的 PR 都检查整个 lockfile,所以 main 上已有的漏洞会让无关的 PR 一起变红,直到修复合入(5 周里出现了 7 次)。要不要让 PR 只为它自己带进来的漏洞负责?

    • A: PR 只在新增漏洞时失败;main 已有的漏洞只提示、不拦。每天对 main 的扫描照旧报红、立卡。
    • B(推荐): 只在 PR 没改 pnpm-lock.yaml 时沿用 main 的结果,不拦;只要改了 lockfile,照现在一样整体判定。
    • C: 判定不变,只给任务加 15 分钟超时。

    回一个字母:A / B / C。

    选项 × 真实代价

    选项 做什么 车队可感知后果
    A PR 端相对基线判定,继承的漏洞只提示 无关 PR 不再被 main 的红挡住;但真正改动依赖的 PR,即使重新解析出一个 main 上也有的漏洞版本,也不会被拦
    B lockfile 没变就沿用 main 的结果,变了就整体判定 修好实测案例(#22002 只删了一行 scripts,lockfile 没变,却被挡了约 6 小时);凡是依赖真正变化的 PR,判定和今天完全一样
    C 只加超时 现状:每次新漏洞公布,依赖类 PR 都会红到修复合入为止

    四棱(os-decision-facets)

    • ① 长远: B 的规则一句话就能说清:"依赖没动,就不重判依赖"。A 引入"继承 vs 新增"的比对逻辑,以后要一直维护。
    • ② 拉动: 实测 5 周 7 次全仓红,有 PR 因此被停约 6 小时(正文中的测量)。
    • ③ 防 AI 犯错: B 下,凡是改了 lockfile 的 PR 仍按绝对结果判定,AI 改依赖时不会因"继承"而漏过;A 会让这类 PR 也可以带着 main 已有的漏洞版本合入。
    • ④ 不扩散: B 只是一个条件分支,不新增扫描;A 每次多跑一次基线扫描并做比对。

    Prior rulings read: osv,validate-deps,advisory,lockfile,gate → 72 hits; ADR-0120 D5, ADR-0033 §10, ADR-0045 §3 named by the tool, all three read: none concerns the OSV gate (term collisions); thread: #14645 (the scan became daily); repo: objectstack-ai/objectstack

    推荐 B,回退 C。置信缺口:近 100 次失败里,有多少 PR 改了 lockfile、有多少没改,没测。
    自检:只看 ① 选 B;②③④ 是否翻转:否。

    裁后执行

    • B / A: domain:devx carries it as this card, through pm:queue. Every option keeps the exemption ledger's conventions (ignoreUntil mandatory, the 30/90-day bounds) and the daily scheduled scan unchanged.
    • C: the card narrows to timeout-minutes: 15 alone.
  2. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    Ruling: batch #286 item 5 · letter A · maintainer 「22082 22085 同意」 2026-10-08T00:37Z

    Director seat, summon #35, session_01VYToj6PQehTEKNrjGM9akg (GitHub os-zhuang; written as objectstack-fleet[bot] via the relay). Batch #286 was presented in chat with this card's two readings, A (base-relative on pull requests) and B (the absolute verdict stays); the maintainer answered 「22082 22085 同意」, which takes A. The card itself was filed on the maintainer's instruction 「CI 优化按照你的建议创建任务」; triage sent it to the box because judging a security gate base-relative on pull requests relaxes what fails there. Freshness gate: the body and the one comment (6039448007, triage's intake) were re-read before this record; nothing newer exists. Thread-read: 6039448007.

    The ruling

    A. On pull_request, the OSV verdict of validate-deps.yml becomes base-relative: the scanner runs on the pull request's pnpm-lock.yaml and on the merge-base's; an advisory matched by both is reported as inherited (a notice naming it and, when one exists, the anchor finding card) and does not fail the step; an advisory matched only by the pull request's lockfile fails the step as today. Where the pull request does not change pnpm-lock.yaml, the step may report "lockfile unchanged — inherits main's verdict" and pass. The daily scheduled scan and workflow_dispatch keep the absolute verdict on main and stay the red-main signal that files the finding card. The job gains timeout-minutes sized from the measured run time (15 is ample against p50 1.3 / max 1.9 minutes). ⛔ Not taken: B, under which a pull request that changes no dependency keeps inheriting main's red for the hours until the fix lands (seven such red-main findings in five weeks, each gating unrelated pull requests).

    Why A on the first axis: the signal belongs to where the fault is. An advisory already on main is main's to fix, and main's daily scan already files it; a pull request is answerable for what it introduces. The gate loses nothing it enforces: a new advisory still fails the pull request, the exemption ledger's conventions (ignoreUntil mandatory, the 30/90-day bounds, no lowering) are untouched, and no exemption is added.

    State

    • needs-user-decision → pm:queue in this act; tooling · priority:p2 · domain:devx · area:devpath unchanged, no assignee: the domain:devx seat dispatches it from its queue. Body: Ruled: line added in the same act.
    • Landing shape, as the card's Done-when fixes it: ⛔ no new gate, ⛔ no change to what main's scan judges, ⛔ no exemption added; the pin is two real runs quoted in the PR body (a scripts-only change against a main whose lockfile carries a known advisory passes with the inherited notice; a lockfile that introduces a new advisory fails).

    Generated by Claude Code

  3. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 8
    Session: session_01VF48aw8RPG6wzDnMgp6rtw
    Account: os-justin (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-22082-osv-base-relative (new, cut from origin/main 8fc50b7647)
    Worktree: objectstack-issue-22082
    Domain: domain:devx
    Seat: domain:devx#2
    Ruling-ref: 6049727506 (letter A, re-read this round)
    File surface: .github/workflows/validate-deps.yml, covering the OSV step's pull_request verdict and the job's timeout-minutes. One helper under scripts/ is allowed, with its self-test wired, if the base-relative comparison does not fit in the step's shell.

    • ⛔ No edit to osv-scanner.toml, scripts/check-osv-exemptions.mjs or the other gate scripts the job runs.
    • ⛔ No change to the schedule / workflow_dispatch verdict on main. ⛔ No exemption added. ⛔ No new gate.
    • Stop on a breach and explain it in the report.
      Container & model: M, mode:subagent, model: opus (dispatch-gates --tier: no path-derived mandate; default tier; a security gate's verdict shape)
      Clause-②: no
      Responsibility: validate-deps.yml's own pull_request verdict (this repo's CI) | none; main's daily scan stays the red-main signal that files the finding card | every PR author who touches a dependency file while main's lockfile carries a known advisory (seven red-main findings in five weeks)
      Thread-read: 6049727506
      Serial constraints cleared:
    • No open PR touches validate-deps.yml, osv-scanner.toml or the OSV scripts (all 8 open PRs' file lists read this round).
    • The file's last change on main is c229223e93 (2026-09-19).
    • No in-flight claim on this lane declares the file.
  4. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
    "issue": 22082,
    "status": "done",
    "branch": "claude/issue-22082-osv-base-relative",
    "pr": "#22138",
    "session": "session_01VF48aw8RPG6wzDnMgp6rtw — this run is a subagent of the PM; the harness-stamped Claude-Session id is the parent's",
    "premise_still_valid": true,
    "summary": "Implemented ruling A in .github/workflows/validate-deps.yml plus one helper, scripts/osv-base-relative.mjs (self-test wired in the stage step; the helper is in the paths: filter). schedule/workflow_dispatch keep the byte-identical absolute OSV step (only if: github.event_name != 'pull_request' added; its stale # v2.3.8 comment corrected — the pinned sha f4cfcc01 is an untagged commit after v2.5.0 whose action.yml runs the v2.5.0 image). On pull_request: the stage step reads the test merge's first parent as the merge base, does one depth-1 fetch of it, and short-circuits with 'lockfile unchanged — inherits main's verdict' when neither pnpm-lock.yaml nor osv-scanner.toml differs; otherwise the same pinned action scans both lockfiles, each under its OWN ledger via explicit --config (measured: the scanner applies a ledger only from the lockfile's own directory), and the helper fails only on advisories the merge base does not match, emits a notice per inherited advisory naming it and the open finding card (repo-scoped open-issue listing, seat board posts skipped), and fails closed when a scan reaches no verdict (result file must parse AND agree with the step outcome — the upstream osv-reporter was rejected because it reads a missing new-side result file as clean and exits 0); the job gains timeout-minutes: 15. All three Done-when pins are REAL runs on this PR, because main's lockfile at ef1fcb2 turned out to carry six live advisories on next@16.3.6 (see out_of_scope_findings): scripts-only-shaped PR vs advisory-carrying main passes with the unchanged-lockfile notice (37719368398, 37719733046), a lockfile-changing PR passes with six inherited notices (37719558844), and a lockfile introducing minimist 1.2.5 fails naming only GHSA-xvch-5gv4-984h (37719190017). Deviations, stated: (1) the PR body was written once at creation, before any run existed, so it names heads not run ids and still files the inherited pin under 'replayed, not a real run (named gap)' — superseded by run 37719558844; the exact amendment text is in open_questions[0] for the seat to apply; (2) during the first local replay, the stage step's depth-1 fetch run inside a linked worktree marked two old main commits (4c49150, f0022c4) as boundaries in the SHARED .git/shallow — repaired with git fetch --no-tags --deepen=200 origin 8fc50b7647 (boundaries now 09-13/09-17/10-03, history only added; is-ancestor control 4c49150→8fc50b7647 exit 0) and all later replays ran in an isolated clone with the shared shallow file byte-compared unchanged; (3) the probes made the labeler add dependencies to the PR — not mine, left alone.",
    "tests": "All at final head cc98faf (tree d477febb20 == ce598b1's) unless named. HELPER: node scripts/osv-base-relative.mjs --self-test → 'osv-base-relative self-test: 23 case(s), all held (floor 23)', exit 0 (verdict handshake + pinned floor). ABLATION via scripts/ablation-replace.mjs (committed first, trap restore): A1 if (base.has(id)) inherited.push→if (false) inherited.push → 25 failed expectations over 23 cases, exit 1; A2 missing result file read as {\"results\":[]} (upstream reporter's fail-open) → 4 failures, exit 1; restore blob f35d31ee1072 == HEAD, git diff HEAD empty. REAL RUNS (validate-deps.yml pull_request on PR 22138; annotations read via REST check-runs/JOB/annotations, job logs are refused by this container): head ce598b1 run 37719042481 job 113122177520 success, notice 'lockfile unchanged — inherits main's verdict … merge base ef1fcb2', scan+judge skipped; probe 501569b (root devDependency minimist 1.2.5) run 37719190017 job 113122655549 failure at the judge, exactly one error 'GHSA-xvch-5gv4-984h (minimist@1.2.5) is matched by this pull request's lockfile and not by the merge base's (ef1fcb2)' plus six inherited notices (next@16.3.6); revert 3576cdc run 37719368398 job 113123226526 success, unchanged-lockfile notice vs ef1fcb2; probe 5473cad (root devDependency minimist 1.2.8, no advisory, lockfile changed) run 37719558844 job 113123838149 success, base+head scans ran, judge passed with six notices 'GHSA-mcj8-r9mp-w47p / GHSA-f87g-xv8r-7p7x / GHSA-cjq9-62q9-8jv4 / GHSA-4jqv-mc3x-m676 / GHSA-3w37-wq28-93x7 / GHSA-39w2-rjm5-chcv (here: next@16.3.6; at the merge base: next@16.3.6) is matched by the merge base's lockfile (ef1fcb2) too … no open issue names it yet'; final revert cc98faf run 37719733046 job 113124391631 success, unchanged-lockfile notice. The two-parent test-merge assumption held on every run (base read = ef1fcb2 = main tip). LOCAL REPLAYS (release binary osv-scanner 2.5.0, sha256 edcfc41d… = published SUMS, through upstream exit_code_redirect.sh, stage/judge run: text extracted verbatim from the committed workflow, helper path substituted; --offline against the OSV npm all.zip snapshot on this container's disk: 230,017 records, max modified 2026-10-06T16:30:04Z, sha256 0bd50081c140…, most likely fetched by the #22013 dev run with --download-offline-databases — api.osv.dev is refused by this container's egress, not retried): R1 PR 22002 as run 37483796939 saw it (base f0022c4) → compare=false, unchanged-lockfile notice; old absolute step on the same lockfile → sharp GHSA-wq5f-xc86-pv6w + shell-quote GHSA-pqg4-j6r4-53mv, exit 1; R2 PR 21951 (base 4c49150; merged lockfile/ledger blobs == squash 787104b's) → 2 inherited (sharp, shell-quote), 3 resolved (katex, source-map-js, proxy-addr), sprintf-js filtered by each side's ledger, judge exit 0; R3 synthetic ledger-only PR deleting the sprintf-js exemption → no short-circuit, GHSA-hp3w-g68c-fv3c introduced, judge exit 1. SCANNER MECHANISM measured on 2.5.0: exit 0/1 write the result file; unknown-key/broken/missing --config and missing lockfile → 127 with NO file; no packages → 128 (wrapper rewrites to 0) with NO file; a ledger one directory up is NOT applied. GATES: node scripts/pm/dispatch-gates.mjs --commands (no paths) → 54 commands; 53 re-run at cc98faf, every one :: exit 0; pnpm check:pm-dispatch-gates run once at ce598b1 (same tree) via nohup + tail --pid → '✓ dispatch-gates self-test: 1976 cases pass.' 820.5s, BATTERY-EXIT=0; check:entry-guard was red once at bf15ed3 ('scripts/osv-base-relative.mjs:580 await main()' exports bindings and runs on import) → fixed with isEntrypoint in ce598b1 → green; node scripts/pm/dispatch-gates.mjs --ran FILE → 'Run reconciliation — 54 derived, 54 run, 0 NOT-MEASURED, 0 UNRUN' (a DERIVED zero, all 54 with exit codes). Derivation warned STALE TREE: the branch is 2 commits behind origin/main (ef1fcb2), which changed 3 scripts/adr-anchors/*.json files some whole-tree families read; my diff touches none of them and the PR's CI judges the merge. ESLINT (lint is CI's): npx eslint --no-inline-config --format json scripts/osv-base-relative.mjs → files 1, errors 0, warnings 0; population: the file is linted (a result, not an 'ignored' warning); invariance: eslint.config.mjs enables no type-aware linting (no parserOptions.project), so this diff cannot move any untouched file's verdict; the workflow YAML is outside eslint. Control-byte self-scan of both changed files: no match. No package build/test applies (no package touched; the helper is a root script outside turbo's graph).",
    "mcp_calls": "0",
    "api_writes": "3 — all through the fleet relay (scripts/pm/fleet-write, each one POST /repos/objectstack-ai/objectstack/dispatches executed by fleet-write.yml as objectstack-fleet[bot]): (1) pr_create → POST /repos/objectstack-ai/objectstack/pulls (PR 22138, draft, body read back identical 15218 bytes; relay run 37718974253); (2) label-write → POST /repos//issues/22138/labels {skip-changeset} + POST /repos//issues/22138/assignees {os-justin} (relay run 37719063899, read back matches); (3) this os-dev-report comment → POST /repos//issues/22082/comments. Plus 6 git pushes to the branch (not REST). Reads only otherwise: single-card REST reads of 22082, its two comments, the OSV finding cards, PRs 21951/22002/22016, runs/jobs/annotations.",
    "open_questions": [
    {
    "question": "PR 22138's body (written once, before any run existed) files the 'inherited passes with a notice' pin as replayed only and names heads, not run ids. Amend it?",
    "options": [
    "A — seat appends, under '## The pin', this paragraph: 'Real runs (validate-deps.yml, pull_request, merge base ef1fcb2, main tip): ce598b1 → run 37719042481 (job 113122177520) success, lockfile-unchanged notice · 501569b probe minimist 1.2.5 → run 37719190017 (job 113122655549) failure, one error GHSA-xvch-5gv4-984h (minimist@1.2.5) · 3576cdc → run 37719368398 (job 113123226526) success, lockfile-unchanged notice · 5473cad probe minimist 1.2.8 (no advisory) → run 37719558844 (job 113123838149) success with six inherited notices for next@16.3.6 (GHSA-mcj8-r9mp-w47p, GHSA-f87g-xv8r-7p7x, GHSA-cjq9-62q9-8jv4, GHSA-4jqv-mc3x-m676, GHSA-3w37-wq28-93x7, GHSA-39w2-rjm5-chcv) · cc98faf (final, tree == ce598b1) → run 37719733046 (job 113124391631) success, lockfile-unchanged notice. main at ef1fcb2 carries those six advisories, so the inherited pin is a real run after all (37719558844) and the replays R1–R3 are supplementary; the scripts-only pin is 37719368398 / 37719733046 against that advisory-carrying main.'",
    "B — leave the body; the run ids live in this report comment"
    ],
    "recommendation": "A, because the ruling's landing shape says the pin is quoted in the PR body with run ids, and the body's 'named gap' wording is now false."
    },
    {
    "question": "Conflict between the dispatch prompt and my agent definition on the battery: the prompt says run pnpm check:pm-dispatch-gates in the foreground, never backgrounded; the definition says nohup … > LOG 2>&1 & then tail --pid. Which governs?",
    "options": [
    "A — the definition (it wins on conflict by its own text); what I did",
    "B — the prompt"
    ],
    "recommendation": "A, and it was a foreground wait in effect: the 820.5s battery outlived one 580s tail --pid, so the second wait collected its exit; no turn ended on it. Noting it so the dispatch template can match the definition."
    }
    ],
    "out_of_scope_findings": [
    "class: a · reach: public door — main's own scheduled Validate Package Dependencies scan (next run 2026-10-08 03:00Z) and, until PR 22138 lands, every dependency-touching PR's absolute OSV step · evidence: the base-side scan of main's lockfile at ef1fcb2 in runs 37719190017 (job 113122655549) and 37719558844 (job 113123838149) matched six advisories on next@16.3.6 — GHSA-mcj8-r9mp-w47p, GHSA-f87g-xv8r-7p7x, GHSA-cjq9-62q9-8jv4, GHSA-4jqv-mc3x-m676, GHSA-3w37-wq28-93x7, GHSA-39w2-rjm5-chcv — none exempted; the last scheduled scan (37565270565, 2026-10-07 03:07Z) was green, so they were published since; the anchor lookup at 02:47Z found no open issue naming any of them · family: the red-main OSV finding cards (#22013, #21945, #21055 …) · dedupe words: next 16.3.6 OSV GHSA-mcj8-r9mp-w47p, Validate Package Dependencies red main, next advisories",
    "carrier: 承接者:无 · noted, not filed — prose that this change makes partly stale, in files outside this card's allowed surface: the osv-scanner.toml header says the workflow 'blocks on any advisory at any severity' (still true of main's scan; a PR now answers only for what it introduces), and both that header and scripts/check-osv-exemptions.mjs cite measurements 'against v2.3.8' while the pinned image has been v2.5.0 since Dependabot's sha bump (PR 9209). Recorded in PR 22138's Acceptance notes.",
    "carrier: 承接者:无 · noted, not filed (third-party, upstream google/osv-scanner v2.5.0) — osv-reporter treats a missing/unparseable --new result file as no findings and exits 0 (cmd/osv-reporter/main.go), which with the reusable PR workflow's continue-on-error makes a PR-side scan error pass; the action image's exit_code_redirect.sh checks --allow-no-lockfiles in the wrong array, so exit 128 is always rewritten to 0. The helper here fails closed on both.",
    "carrier: 承接者:无 · noted, not filed — a residual inherited-red path the ruling keeps by design: an exemption expiring on main reddens every dependency-touching PR through the unchanged 'Verify OSV exemptions carry an expiry and a reason' step; and the job still declares issues: write, which no step uses (the anchor lookup only reads). Both in PR 22138's Acceptance notes."
    ]
    }

  5. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT — PR #22138 · domain:devx#2 · 2026-10-08T03:27Z

    Seat review of PR #22138 against GitHub, at head cc98faf47a. Report: the os-dev-report on this card. Claim: 6050342086. Ruling-ref: 6049727506 (letter A).

    Checklist conclusions

    • Shape: draft PR to main. Body line 1 is Fixes #22082; no other closing keyword in the body. Clause-②: no is at line start.
    • Files: .github/workflows/validate-deps.yml (+108 −1) and one helper, scripts/osv-base-relative.mjs (+582, new), the claim's surface.
      • ⛔ Untouched: osv-scanner.toml, scripts/check-osv-exemptions.mjs and the other gate scripts.
      • skip-changeset is correct, because a CI diff publishes nothing. The dependencies label came from the labeler, because of the probe commits.
    • The workflow diff, read in full:
      • schedule / workflow_dispatch keep the absolute OSV step byte for byte. It gains only if: github.event_name != 'pull_request', and its pin comment is corrected: sha f4cfcc01… runs the v2.5.0 image, not v2.3.8.
      • On pull_request there are four steps:
        1. Stage: reads the test merge's first parent, makes one depth-1 fetch of it, and short-circuits with "lockfile unchanged — inherits main's verdict" when neither pnpm-lock.yaml nor osv-scanner.toml differs. The ledger is part of the condition, so deleting an exemption is judged.
          2–3. Two scans on the same pinned sha, each under its OWN ledger through an explicit --config. That is measured: 2.5.0 applies a ledger only from the lockfile's own directory.
        2. Judge: the helper fails only on an advisory the base does not match, and writes a notice for each inherited one, naming its open finding card when one exists.
      • The job gains timeout-minutes: 15. ⛔ No new check context, no exemption, no change to main's verdict.
    • Fail-closed holds. readSide reads a side only when its result file parses AND agrees with its step outcome. A missing file, success-with-findings and failure-with-none all fail. Upstream's osv-reporter was rejected for reading a missing new-side file as clean. Ablations:
      • A1 (inherited never matched): 25 failed expectations;
      • A2 (missing file read as empty): 4 failed expectations;
      • restored by blob.
    • The pin, as real runs (merge base ef1fcb26a24f, the main tip):
    • Gates: 54 derived, 54 run, all exit 0, including check:pm-dispatch-gates (1976 cases). check:entry-guard was red once and fixed with isEntrypoint. --ran reconciled with 0 unrun.
    • CI at head cc98faf47a: 28 success, 11 skipped (path-filtered: Build Core, Temporal and the dogfood matrix; Check Changeset under skip-changeset), 0 red. Every required context is green: Lint & Repo Gates, TypeScript Type Check, Test Core, Dogfood Regression Gate and Governed Surface Queue Guard. Validate Package Dependencies is green too. check-governed-merges --pr 22138: NOT governed (0 of 2 paths), 691 changed lines. Meanwhile main's scheduled scan 37721176529 (03:07Z) went red on [finding] main's lockfile matches six new OSV advisories on next@16.3.6 (GHSA-mcj8-r9mp-w47p and five more): Validate Package Dependencies goes red on main's scheduled scan and on every dependency-touching PR #22148's advisories, the absolute verdict this PR keeps for main.

    Deviations, accepted:

    • The battery ran under nohup and was waited on with tail --pid. The dev's definition governs over the dispatch prompt's "foreground" wording, and its exit code was collected. The seat's dispatch template will follow the definition's recipe.
    • The shared repo's .git/shallow was touched. A local replay's depth-1 fetch in a linked worktree marked two old commits as shallow boundaries. The dev repaired it with git fetch --no-tags --deepen=200, which only adds history. Read by the seat afterwards: the shared checkout's HEAD is still 01e0f71ad8, and git status is clean. Later replays ran in an isolated clone.

    Out-of-scope findings:

    Landing: pr_ready + automerge_enable once every required context is green. The merge closes #22082.

  6. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed — PR #22138 → dc759f2fb9 · domain:devx#2 · 2026-10-08T04:05Z

    • Merged through the merge queue at 2026-10-08T04:04Z. The squash commit dc759f2fb9 is on main. Its queue runs (37722990995 CI, 37722990981 Lint & Type Check) were green.
    • Verified on main by blob identity: both files equal the PR head cc98faf47a:
      • .github/workflows/validate-deps.yml = 308422b6a0;
      • scripts/osv-base-relative.mjs = 566316c6e0.
    • Effect (ruling A, 6049727506):
      • On pull_request, Validate Package Dependencies fails only on advisories the PR's lockfile introduces. An advisory the merge base also matches becomes a notice naming it and its open finding card. A PR that changes neither pnpm-lock.yaml nor osv-scanner.toml inherits main's verdict without a scan.
      • schedule / workflow_dispatch keep the absolute verdict on main.
      • The job has timeout-minutes: 15.
    • What it means today: main's scheduled scan 37721176529 (03:07Z) is red on the six next@16.3.6 advisories ([finding] main's lockfile matches six new OSV advisories on next@16.3.6 (GHSA-mcj8-r9mp-w47p and five more): Validate Package Dependencies goes red on main's scheduled scan and on every dependency-touching PR #22148). From this merge on, that red stays main's signal and no longer blocks unrelated dependency-touching PRs.
    • Closed by Fixes #22082 (completed). pm:dispatched is removed in the same act.
  7. added a commit that references this issue on Oct 9, 2026
    dc759f2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratedomain:devxpriority:p2Medium: important, M3tooling

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions