From e6a3636f797528744dc4055ad4f324269d150c5b Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 6 Oct 2026 04:46:55 +0000 Subject: [PATCH 1/2] chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 No fixed sprintf-js exists: 1.1.3, the latest release, is the last affected version. It reaches the lockfile only through tedious 18.6.2 (driver-sql's optional mssql peer) and fengari 0.1.5 (under ioredis-mock, a service-cluster-redis devDependency), and the latest release of each still declares ^1.1.3. The entry carries a bare-date ignoreUntil 30 days out and an advisory-linked reason, per the ledger's header conventions. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude --- osv-scanner.toml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/osv-scanner.toml b/osv-scanner.toml index 582ce02e64f..425be399517 100644 --- a/osv-scanner.toml +++ b/osv-scanner.toml @@ -83,3 +83,8 @@ # # Verify locally: node scripts/check-osv-exemptions.mjs # Prove the check: node scripts/check-osv-exemptions.mjs --self-test + +[[IgnoredVulns]] +id = "GHSA-hp3w-g68c-fv3c" +ignoreUntil = 2026-11-05 +reason = "https://github.com/advisories/GHSA-hp3w-g68c-fv3c — no fixed sprintf-js exists (1.1.3, the latest release, is the last affected version), and it arrives only transitively through tedious 18.6.2 (driver-sql's optional mssql peer) and fengari 0.1.5 (under ioredis-mock, a service-cluster-redis devDependency), whose latest releases (tedious 20.3.3, fengari 0.1.5) still require ^1.1.3; remove when sprintf-js publishes a fix or both parents drop it." From ba17ca5bb2010a05a41209c245f8722c6a5d2add Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 6 Oct 2026 05:12:46 +0000 Subject: [PATCH 2/2] chore(osv): keep the ledger header's self-description true while an entry stands The header said the ledger "currently holds ZERO exemptions", which stops being true the moment the sprintf-js entry lands. It now states zero as the intended steady state and says every entry is a dated exception with its own renewal date. The rest of the header is byte-identical. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude --- osv-scanner.toml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/osv-scanner.toml b/osv-scanner.toml index 425be399517..74888c5ce29 100644 --- a/osv-scanner.toml +++ b/osv-scanner.toml @@ -8,8 +8,9 @@ # yet, where the alternative is pinning a required check red indefinitely, and # a permanently red required check is worth exactly as much as no scan at all. # -# This ledger currently holds ZERO exemptions. That is the intended steady -# state, not a coincidence — read the whole header before you change it. +# This ledger's intended steady state is ZERO exemptions, not a coincidence: +# every entry below is a dated exception with its own renewal date. Read the +# whole header before you change it. # # --------------------------------------------------------------------------- # Three conventions govern every entry (decided on #4965)