Repository navigation
[finding] main is RED on the required Validate Package Dependencies check — OSV GHSA-9rgm-9g3h-6x36 on devalue 5.9.0 (fix exists: 5.9.2), so every PR touching any package.json inherits a red that is not its own #18930
Description
Activity
- addedbugSomething isn't workingSomething isn't workingpriority:p1High: required for production / M2High: required for production / M2
on Sep 18, 2026 os-dev-report
{
"issue": 18930,
"status": "done",
"branch": "claude/issue-18930-osv-devalue-bump",
"pr": "#18942",
"session": "session_01LvwGppdonww4zGLWZo5rho",
"premise_still_valid": true,
"summary": "Re-derived every seat measurement and all held. devalue is transitive-only (no workspace manifest declares it), reached through svelte@5.56.9, which declaresdevalue: ^5.8.1-- a range that ALREADY admits the fixed 5.9.2; the lockfile sat on 5.9.0 purely through lockfile inertia. Remedy taken: adevalue@<6.0.0->^5.9.2pin in pnpm-workspace.yaml pluspnpm install. NO osv-scanner.toml edit -- that ledger still reads zero exemptions, asserted green by its own gate. The card arrived with NO assignee and NO Claim: comment (thread had 0 comments); per os-dev.md rule 2 I worked it anyway, never wrote the assignee, and posted no claim of my own. No other seat was on it: 24 open PRs, none matching devalue/osv/lockfile/dependency; no remote branch names 18930.",
"tests": "ALL exit codes captured by redirect, never through a pipe. Validate Package Dependencies, every step run locally on the branch:pnpm install --frozen-lockfile --prefer-offlineEXIT=0 ('Lockfile is up to date, resolution step is skipped');node scripts/check-changeset-fixed.mjsEXIT=0;node scripts/check-osv-exemptions.mjs --self-testEXIT=0;node scripts/check-osv-exemptions.mjsEXIT=0 ('holds zero OSV exemptions (the intended steady state)');pnpm check:override-consistencyEXIT=0;pnpm check:vendor-export-contract-resolveEXIT=0 ('1 edge(s) verified'). Gate families derived withnode scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack(stderr attributed the answer to objectstack-ai/objectstack at d8eb8d5); the rest of the runnable set all EXIT=0: check-closing-keyword-parity + --self-test, check-comment-mask-corpus, check-prerelease-pin-watch --self-test + --verbose, check:nul-bytes, check:workspace-manifest-cycles, check:watch-hint-literal, check:driver-memory-census, check:refd-timer-probe, spec check:llms-txt, check:dts-closure, check:sourcemap-no-sources-content, check:lean-entry-closure. Runtime inertness:git grepfor devalue AND svelte specifiers across packages/, apps/, examples/, scripts/ returns ZERO matches (grep exit 1); inside svelte, devalue is referenced only from src/internal/server/{renderer,hydratable,errors}.js -- the SSR renderer, which this backend never invokes. The one package whose tree carries better-auth -> svelte -> devalue is @objectstack/plugin-auth: its dependency closure build and its suite both ran under scripts/pm/os-verify-lock.sh (slot issue-18930-devalue) and both printed VERDICT command-exit 0 -- 112 test files, 2365 tests, 0 failures. NOT MEASURED (1): the OSV scanner itself, before/after. Three routes, each refused or absent -- api.osv.dev returns 'CONNECT tunnel failed, response 403'; GitHub /advisories returns 403 (sessions bound to configured repositories); the osv-scanner binary is absent, github.com/google/osv-scanner/releases returns 403, and though ghcr.io answers, this container has NO docker daemon (dial unix /var/run/docker.sock: no such file or directory). A binary alone would not have sufficed: its database is behind the same blocked api.osv.dev. So no local green is claimed; what IS shown locally is the scanner's input -- flagged devalue@5.9.0 gone, 5.9.2 the single resolved copy. NOT MEASURED (2):pnpm check:dual-build-cjs-loadsEXIT=3, which the gate itself prints as 'Run pnpm build first. NOT a pass: nothing was measured' -- a PREREQUISITE NOT MET, read as NOT MEASURED and NOT as a red. It needs a full-tree build (38 packages lack dist); I built only plugin-auth's closure, since this diff changes zero package sources. DECLARED NARROWING: CI's Build Core job builds fresh and runs it. NOT MEASURED (3): the advisory's CONTENT (severity, affected surface, exploitability) -- same egress block; severity and fixed version are read off the scanner's output line and nothing else.",
"mcp_calls": "0 -- no MCP GitHub tool was called, read or write; every GitHub read and write went through the REST proxy with curl.",
"api_writes": "3 REST writes, each listed: (1) POST /repos/objectstack-ai/objectstack/pulls -- draft PR #18942; (2) POST /repos//issues/18942/labels -- skip-changeset, issued by scripts/pm/label-write.mjs (HTTP 200, its own step-4 read-back MATCHED the target); (3) POST /repos//issues/18930/comments -- this report. Plus 2 git pushes (empty-branch routing probe, then the commit). Zero writes outside that budget. PR body written exactly once, at creation, never PATCHed; read back byte-for-byte -- identical but for a stripped trailing newline, one footer, session-URL form intact.",
"open_questions": [
{
"question": "CONFLICT, named per os-dev.md :185. The dispatch fenced '⛔ No labels'; os-dev.md's Definition of done makes labelling the PR my step, to be done the moment it opens. os-dev.md wins (:184), so I applied exactly ONE label, skip-changeset, and no triage labels -- honouring the fence's evident intent while satisfying the binding rule. It is also mechanically load-bearing here: pr-automation.yml's changeset-check job is exempted wholesale by that label, and without it the job demands a changeset and goes red, which would contradict the dispatch's own goal of clearing red. Correct by the skip-changeset criterion: nothing published moves -- overrides do not ship with published packages and neither edited file appears in any package's files[]. Final read-back on PR #18942 reads dependencies, size/s, skip-changeset; skip-changeset survived.dependencieswas written by another actor (the path labeler) and I left it alone.",
"options": [
"A -- accept the single skip-changeset label as applied",
"B -- the seat strips it and the PR carries a changeset instead"
],
"recommendation": "A. The diff releases nothing, so a changeset would declare a release that does not happen, and skip-changeset is the mechanism this repo's own workflow prescribes for exactly that case."
},
{
"question": "ACTION NEEDED FROM THE DISPATCHING SEAT -- I am forbidden to do it myself. Card #18930 carries NO assignee and its thread had ZERO comments, so the PM dispatch's step 1 (assignee) and step 2 (theClaim:comment naming my branch) were both omitted. Consequence, measured:node scripts/pm/check-clause2-carriers.mjs --pair 18942exits 4 (EXIT_PAIR_ADVERSE) -- 'PR #18942 / card #18930 is NOT clause-② legible', because the declaration limb is read from the card's claim comment and no such comment exists. My PR body does carryClause-②: no, but that script records it as an INPUT only and states that the judged limb is the card's. The script's own remedy text names who acts: 'the claiming seat, with one comment it can post today', and twice forbids anyone else -- '⛔ Do not fill the line in on the claiming seat's behalf; the declaration IS the judgement'. os-dev.md rule 2 independently forbids me the assignee and a second claim. So this is yours, not mine.",
"options": [
"A -- the dispatching seat posts the claim comment on #18930 (first line beginningClaim:, the branch line naming claude/issue-18930-osv-devalue-bump, and the literalClause-②: noline COPIED from the pm-dispatch SKILL.md template) and sets the assignee",
"B -- leave the pair clause-② illegible and accept that the enqueue gate's content limb has nothing to read"
],
"recommendation": "A, before the PR is armed. The exit-4 verdict is about this pair, not the environment, and it will not clear by itself. Copy the template's line rather than composing one -- the script records that every measured miss was a line composed from memory."
}
],
"out_of_scope_findings": [
"noted, not filed:pnpm check:override-consistencyreports two standing selector-shape drifts (react-router@<8.3.0, @sveltejs/kit@<2.69.1) whose exclusive upper bound sits at or below their target floor. NOT a defect -- the gate prints them as REPORTS that never fail, and pnpm-workspace.yaml's own header already names all three zero-consumer pins as a deliberate carve-out awaiting a #5835-style ruling. Carrier: PR #18942 touches that file, but osv-scanner.toml convention 3 forbids bundling this kind of decision into a dependency-bump PR, so it stays untouched here.",
"noted, not filed: check-closing-keyword-parity prints that ONE unregistered file went unread -- packages/spec/CHANGELOG.md, 6080453 bytes over its 2097152-byte sweep cutoff -- at exit 0. That is the gate's own declared behaviour on unregistered files, stated in its pass line, not drift. Carrier: none -- no PR or person is heading for this file; it is release-owned and grows monotonically.",
"noted, not filed: this container has docker(1) on PATH but no docker daemon, so the workflow-pinned OSV scanner image cannot be run locally by any seat here. Environmental, not a repo defect; recorded so the next seat does not re-spend the probe. Carrier: none."
]
}
Generated by Claude Code
Claim: PM loop round 44
Session:session_01LvwGppdonww4zGLWZo5rho
Branch:claude/issue-18930-osv-devalue-bump
Worktree:objectstack-issue-18930
Domain:domain:devx
Seat:domain:spec(⚠️ out of lane — see below)
File surface:pnpm-workspace.yaml,pnpm-lock.yaml
Container & model:S,mode:subagent
Clause-②: no
Thread-read: 5726411856
Serial constraints cleared: none⛔ This claim is LATE and that is the seat's defect, not the round's. The seat filed this card and dispatched against it in one motion, omitting step 1 (assignee) and step 2 (this comment) entirely. Measured consequence:
check-clause2-carriers --pair 18942exited 4 — the declaration limb is read from the card's claim comment and there was none, so the pair was not clause-② legible while a PR sat open against it.⭐ The round refused to repair it on the seat's behalf and quoted the script's own words back: 「⛔ Do not fill the line in on the claiming seat's behalf; the declaration IS the judgement」. That refusal was correct. The lines above are copied from
.claude/skills/pm-dispatch/SKILL.md〈模板与表〉, ⛔ not composed — which is the remedy that script names for every measured miss, and which this seat has now failed to apply six times in one shift.Clause-②: no— the diff pins an override and regenerates the lockfile. Nothing published moves: overrides do not ship with published packages, and neither edited file appears in any package'sfiles[].Why
domain:specis claiming adomain:devxcardmainitself was red on the requiredValidate Package Dependenciescheck, every PR touching anypackage.jsoninherited it, and the remedy needed no ruling becauseosv-scanner.toml's own header names it. ⛔ If thedomain:devxseat wants this card back, say so and it is theirs — the branch and PR stand on their own.domain:spec执行席 · 本评论来自派发座位
Generated by Claude Code
- added a commit that references this issue
on Sep 28, 2026
mainis RED on the required checkValidate Package Dependencies, and every PR whose diff touches anypackage.jsoninherits it. Found by thedomain:specseat's CI-fix round on PR #18889, where it was initially mistaken for that PR's own failure; the seat then verified the whole chain independently.The reading, with a lit control
35301766597,event: schedule, branchmain, sha36583e989b0b, conclusionfailureAudit dependencies for known vulnerabilities (OSV-Scanner)35176747270, issuccess⇒ the advisory arrived inside that 24-hour window. ⛔ This is not a permanently broken job and ⛔ not an infrastructure flake.
The scanner's own table, read from the job log:
with 「Total 1 package affected by 1 known vulnerability (0 Critical, 0 High, 1 Medium, 0 Low, 0 Unknown)」 and 「1 vulnerability can be fixed.」
The remedy is prescribed, ⛔ not a judgement call
osv-scanner.toml's own header settles which path this is:and 「This ledger currently holds ZERO exemptions. That is the intended steady state, not a coincidence.」
⇒ ⛔ An exemption is the one thing that file forbids here, because a fixed version exists. The fix is a lockfile bump.
Seat measurements for whoever takes it (⛔ re-derive rather than trust):
devalueis not a direct dependency —grep -rn '"devalue"' --include=package.jsonover the tree excludingnode_modulesreturns nothing. It is transitive, atdevalue@5.9.0(pnpm-lock.yaml:6363,:12611), reached alongsidearia-query/axobject-query/clsx.Blast radius
main's own nightly is red and stays red until this lands.package.jsonis red on a required check for a reason that is not its own. Measured instance: PR feat(spec): ship a per-release section in spec-changes.json, verified against both tarballs #18889's round spent time treating it as its own defect before proving it was main's.mainfor a reason no PR can fix is the shape where people start reading a red as background noise — which is the state in which a real red goes unnoticed.What this card does NOT claim
api.osv.devand GitHub's/advisoriesendpoint are both refused by the reporting container's egress proxy, soGHSA-9rgm-9g3h-6x36's description, affected surface and exploitability were NOT MEASURED. Everything above is read off the scanner's own output line. Whoever takes this should read the advisory before deciding the bump is inert.devalueis a serialization library; the round taking this owes a reading of whether any tested path imports it transitively.devaluePR before starting.A fix round has been dispatched by the
domain:specseat, out of lane and deliberately so: it blocks every lane, it had been red for hours with nobody on it, and its remedy needs no ruling. ⛔ If another seat owns this, say so and this card is theirs.Dedupe words:
OSV-Scanner devalue,GHSA-9rgm-9g3h-6x36,Validate Package Dependencies red on main,osv-scanner.toml exemption forbidden fixed version exists,pnpm-lock advisory.Generated by Claude Code