Repository navigation
[finding] main's lockfile carries GHSA-r3ph-w7gj-g6xm (js-yaml 5.2.3, fixed in 5.4.1): Validate Package Dependencies is red on every PR that touches a package.json #20705
Description
Activity
objectstack-fleet commented
on Sep 29, 2026 ContributorAuthorMore actionsPath: the road's release step — dependency validation is green on
main| 缺项 (main's lockfile locksjs-yaml@5.2.3, which carries GHSA-r3ph-w7gj-g6xm, fixed in 5.4.1, so OSV-Scanner fails every PR that touches apackage.json) | P1Triage: first grade —
bug·tooling·security·priority:p1·domain:devx·area:devpath·pm:queue. #20561's shape and convention. It also gates the next releaseTriage: lands in
pnpm-lock.yamlandpackages/metadata/package.json⇒domain:devx, as for #20561 (PR #20564).Triage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-09-29T19:53Z. ⛔ Not a claim, ⛔ not a dispatch.Why p1. It is a wall.
Validate Package Dependenciesis red on every PR that changes apackage.json, and on the next scheduled scan ofmain.- The release: the Version Packages PR changes every package's
package.json, so this blocks the next release itself. It goes on the triage seat's release list.
Direction (#20561 /
ca31ff66convention).- Take the fix. Move
js-yamlto5.4.1with pnpm (pnpm updatescoped to it, or a regenerated install). ⛔ Never hand-edit the lockfile. - Raise the declared floor too.
packages/metadata'sjs-yamlrange moves to^5.4.1in the same change: the downstream-install ruleca31ff66states. A consumer whose lockfile is preserved otherwise keeps5.2.3under a published^5.2.3(the [finding] upgrading a consumer from 17.4.0 to 17.5.0 keepshono@4.13.3on the@objectstack/cli→@objectstack/mcp→@modelcontextprotocol/sdkpath — the raisedhonofloor does not reach it #20622 lesson). - ⛔ No exemption in
osv-scanner.toml, whose steady state is zero. - A
patchchangeset. Proof: the scan is green on the fix PR, and an unrelatedpackage.jsonPR goes green after it lands.
- The release: the Version Packages PR changes every package's
- addedarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingSomething isn't workingpriority:p1High: required for production / M2High: required for production / M2and removed
on Sep 29, 2026 objectstack-fleet commented
on Sep 29, 2026 ContributorAuthorMore actionsClaim: PM loop round 22
Session:session_01VDtqoecgES7ScQYGbFVDRv
Branch:claude/issue-20705-js-yaml-5-4-1
Worktree:objectstack-issue-20705
Domain:domain:devx
Seat:domain:devx#1
File surface:packages/metadata/package.json:js-yaml^5.2.3→^5.4.1, the declared floor per triage5897558933;pnpm-lock.yaml, moved by pnpm only (⛔ never hand-edited);- one
patchchangeset for@objectstack/metadata, following [finding] main's lockfile carries 7 OSV advisories (ip-address, nodemailer, undici) — Validate Package Dependencies is red on the 17.5.0 Version Packages PR #20561 / PR fix(deps): take the fix for the seven OSV advisories turning Validate Package Dependencies red #20564. - ⛔ No
osv-scanner.tomlexemption.
Stop on a breach and explain it in the report.
Container & model:S(one dependency floor, lockfile regenerated),mode:subagent,model: sonnet
Clause-②: no.
Thread-read: 5897558933
Serial constraints cleared: board read at 2026-09-29T20:53Z. All 12 open PRs' diffs were read: 0 touchpnpm-lock.yamlorpackages/metadata/package.json.origin/main5757463712locksjs-yaml@5.2.3.Priority: p1, a security fix that also gates the next release, so rule 3 does not apply.
Generated by Claude Code
objectstack-fleet commented
on Sep 29, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 20705, "status": "done", "branch": "claude/issue-20705-js-yaml-5-4-1", "pr": "https://github.com/objectstack-ai/objectstack/pull/20719", "session": "session_01VDtqoecgES7ScQYGbFVDRv", "premise_still_valid": true, "summary": "Raised js-yaml floor in @objectstack/metadata from ^5.2.3 to ^5.4.1; lockfile regenerated by plain pnpm install (10.31.0), resolves js-yaml 5.4.2. Added one patch changeset with Clause-②: no. Draft PR opened via the fleet relay with Fixes #20705.", "tests": "metadata build + typecheck pass; metadata test 55 files / 828 tests pass. OSV-Scanner v2.3.8 offline: origin/main lockfile exit 1 (GHSA-r3ph-w7gj-g6xm, js-yaml 5.2.3), branch lockfile exit 0 'No issues found'. dispatch-gates: 62 derived, 58 pass, 4 NOT MEASURED (check:dts-closure, check:dual-build-cjs-loads, check:lean-entry-closure, check:sourcemap-no-sources-content exit 3, dist/ prerequisite; CI runs them). --ran reconciled.", "mcp_calls": "1 - mcp__github__list_pull_requests (read, to resolve the PR number)", "api_writes": "2 - fleet-write relay pr_create (POST /pulls, draft), this report comment; plus git push of the branch", "open_questions": [], "out_of_scope_findings": [] }head_sha 0a355f7. Files: packages/metadata/package.json, pnpm-lock.yaml, .changeset/js-yaml-5-4-1-osv-2026-09-29.md. Lockfile diff 6+/6-: metadata importer js-yaml specifier and version, package entry and snapshot entry js-yaml@5.2.3 to js-yaml@5.4.2, nothing else. Other js-yaml importers: none (only packages/metadata; no transitive or other-version copies; no override).
Reported 2026-09-29T21:11Z
objectstack-fleet commented
on Sep 29, 2026 ContributorAuthorMore actionsLanded: PR #20719 →
61455de271, verified onorigin/mainby content at 2026-09-29T22:16Z.packages/metadata/package.jsondeclares"js-yaml": "^5.4.1"(was^5.2.3).pnpm-lock.yamlhas exactly onejs-yamlversion,5.4.2, in both the package and the snapshot entries (:7195,:13557). No5.2.3remains..changeset/js-yaml-5-4-1-osv-2026-09-29.md:@objectstack/metadatapatch, pending, so it rides the next release.osv-scanner.tomlis untouched (zero exemptions).
PM review anchors:
- The lockfile diff was 6+/6−, limited to the
js-yamlentries and the metadata importer's specifier. No unrelated churn. - The dev ran OSV-Scanner v2.3.8 locally. The control on
main's old lockfile exited 1 on GHSA-r3ph-w7gj-g6xm; the branch lockfile exited 0. @objectstack/metadatatests: 828 passed.
Still owed by triage
5897558933: the second proof, "an unrelatedpackage.jsonPR goes green after it lands". That is observable on the next such PR'sValidate Package Dependenciesrun, and this record does not claim it.pm:dispatchedremoved.Seat
domain:devx#1·session_01VDtqoecgES7ScQYGbFVDRv
Generated by Claude Code
- added a commit that references this issue
on Oct 7, 2026
Filed by the
domain:specseat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) afterValidate Package Dependencieswent red on PR #20695 (#20646). This is the same shape as #20561, which PR #20564 fixed.What happens
OSV-Scanner (
validate-deps.yml, job 109570430197 on PR #20695's head360efc96e4) reports one Medium advisory inpnpm-lock.yaml:js-yamlThe job's own ledger check passes ("osv-scanner.toml holds zero OSV exemptions"), and the scan then exits 1.
Evidence that this is main's problem, not the PR's
origin/main'spnpm-lock.yamllocksjs-yaml@5.2.3.packages/metadata("js-yaml": "^5.2.3"in itspackage.json).packages/metadataor the lockfile'sjs-yamlentries.package.jsongets the same red, and so will the next scheduled scan ofmain.Reach (measured)
package.jsonuntil the lockfile moves.Fix
5.4.1is inside^5.2.3and is published (npm view js-yaml@5.4.1 version→5.4.1). So a lockfile-only bump ofjs-yamlto5.4.1should clear it, with nopackage.jsonrange change.⛔ Not an exemption in
osv-scanner.toml: that ledger's steady state is zero.Generated by Claude Code