Repository navigation
[finding] main's lockfile matches four advisories (proxy-addr 2.0.7 critical, source-map-js 1.2.1 high, sprintf-js 1.1.3 no fix, katex 0.16.47): the scheduled OSV scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21945
Description
Activity
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsPath: fleet decision — dependencies carry no known advisory unexempted (
validate-deps.yml,osv-scanner.toml#4965) | 缺项 | noneTriage: first grade —
bug·security·priority:p1·domain:devx·area:devpath·pm:queue(findingremoved). It is release-linked: the version PR touches everypackage.json, so it would go red on this same stepTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-06T03:54Z. ⛔ Not a claim, ⛔ not a dispatch.Triage: lands in the root
pnpm-lock.yaml,osv-scanner.tomland, forkatex,package.jsonpnpm.overrides⇒domain:devx; rationale: these are the same files, and the same lane, as #20705 and #21055 (both closed p1, the same shape).- Why p1:
main's scheduledValidate Dependenciesrun is red.- Every PR touching a
package.jsoninherits the red; PR fix(objectql): a field-narrowed search no longer matches through the companion of a field outside the search-field set #21930 is measured. - The 17.7.0 version PR chore: version packages #21352 rewrites every package's
package.json, so it cannot go green until this lands. Release-priority work is p1 under the maintainer's rule. - One of the four advisories is critical.
- Direction, per advisory, as the card proposes. Each item is its own reviewable change:
proxy-addr2.0.8 andsource-map-js1.2.2 come from a lockfile refresh, because each parent's declared range already admits the fix (the [finding] main's lockfile carries GHSA-r3ph-w7gj-g6xm (js-yaml5.2.3, fixed in 5.4.1):Validate Package Dependenciesis red on every PR that touches apackage.json#20705/[finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055 shape).katex: no publishedmermaidadmits ≥ 0.18.2. Try apnpm.overridesentry first: its only consumer isapps/docs, andcheck:override-consistencyjudges it. Fall back to an exemption only if the docs build breaks on 0.18.sprintf-js: no fixed version exists. An[[IgnoredVulns]]entry withignoreUntiland areason, in its ownosv-exemption-labelled PR, per validate-deps: decide how the OSV gate should express an advisory with no fix available #4965's conventions.
- Measure first: the OSV run's own advisory list was not readable from the filer's container. The claim reads the job log and fixes exactly what OSV reports, not only what npm's bulk endpoint matched.
- ⛔ The OSV step is not loosened and not made optional. ⛔ No blanket exemption.
Generated by Claude Code
- Why p1:
- addedarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingSomething isn't workingpriority:p1High: required for production / M2High: required for production / M2and removed
on Oct 6, 2026 objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsClaim: PM loop round 1
Session:session_01VF48aw8RPG6wzDnMgp6rtw
Account:os-justin(the seat's linked user asGET /useranswers it; the card's assignee)
Branch:claude/issue-21945-osv-lockfile-fixes(cut fromorigin/mainat dispatch)
Worktree:objectstack-issue-21945
Domain:domain:devx
Seat:domain:devx#2
File surface:pnpm-lock.yaml(re-lockproxy-addr→ 2.0.8 andsource-map-js→ 1.2.2).- The
overrides:block ofpnpm-workspace.yaml(akatexentry ≥ 0.18.2). pnpm v10 reads overrides from that file, not from the rootpackage.jsonpnpm.overridesthe card names. osv-scanner.toml: thesprintf-js[[IgnoredVulns]]entry, on a second branchclaude/issue-21945-osv-exemption, in its ownosv-exemptionPR (convention 3, validate-deps: decide how the OSV gate should express an advisory with no fix available #4965). Akatexexemption goes in the same PR only if the override fails the docs build.- Stop on a breach and explain it in the report.
Container & model:M(lockfile re-lock, one override, one exemption entry, two PRs),mode:subagent,model: opus(dispatch-gates --tier --repo objectstack-ai/objectstack: no path-derived mandate; default tier)
Clause-②: no
Thread-read: 6009007076
Serial constraints cleared: board read at 2026-10-06T04:30Z, 7 open PRs, each file list read byfilename. - PR fix(objectql): a field-narrowed search no longer matches through the companion of a field outside the search-field set #21930 (
domain:engine, security(search): a field-narrowed search still matches through the name field's pinyin companion #21880) is the only one touching any of these paths:pnpm-lock.yaml+3/−0 forpackages/qa/dogfood. That path is not inSINGLE_CLAIM_PATHS, so the two PRs run as ordinary concurrency and the later one to land re-locks. - Seat 1's in-flight PR ci(merge-queue): name a no-runner red as infra:no-runner, with a once-per-head re-queue verdict #21946 (ci(merge-queue): a shard that never got a runner is not a test failure #21933) touches
.github/workflows/merge-queue-triage.ymlandscripts/, which is disjoint. - No open PR touches
pnpm-workspace.yamlorosv-scanner.toml.
OSV's own list, read this act: the scheduled run 37407261685 (job 112087469784) names exactly the card's four advisories:
katex0.16.47 → 0.18.2proxy-addr2.0.7 → 2.0.8source-map-js1.2.1 → 1.2.2sprintf-js1.1.3 →--(no fix)
sprintf-jshas no parent-bump route. The latesttedious(20.3.3) and the latestfengari(0.1.5) both still declaresprintf-js ^1.1.3(npm view, this act). So the exemption is the only outlet.Priority rule 3: this is the lane's open P1.
Generated by Claude Code
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 21945, "status": "done", "branch": "claude/issue-21945-osv-lockfile-fixes", "pr": "https://github.com/objectstack-ai/objectstack/pull/21951", "session": "session_01VF48aw8RPG6wzDnMgp6rtw (mode:subagent; this is the dispatching PM's id, and the identity bit is the branch named in claim 6009368904)", "premise_still_valid": true, "summary": "Two draft PRs, both 'Part of #21945'. PR A, #21951 (head e142f120): proxy-addr 2.0.7 to 2.0.8 and source-map-js 1.2.1 to 1.2.2, re-locked through a temporary override pair that was installed and then removed (+11/-11, two packages only), plus the katex override 'katex@>=0.11.0 <0.19.0': '^0.18.2' with its note, in pnpm-workspace.yaml (which resolves to 0.18.10; npm deprecates 0.18.11). PR B, https://github.com/objectstack-ai/objectstack/pull/21952 (head e6a3636f): only the osv-scanner.toml [[IgnoredVulns]] entry for GHSA-hp3w-g68c-fv3c, ignoreUntil = 2026-11-05 as a bare date, a reason in the convention-2 format, labels osv-exemption and skip-changeset. Its body has the 'Exemption decision' section, answered from code with file:line references. Zone 2 premises, each re-measured: (1) at d16b9fbf the OSV set is exactly the four rows, on osv-scanner v2.3.8 AND v2.5.0 (offline DB; api.osv.dev answers 403). (2) Overrides live in pnpm-workspace.yaml; the root package.json pnpm field holds only ignoredBuiltDependencies. (3) Every parent's range admits the fix, but the suggested 'pnpm update ... -r --depth Infinity' dragged 11 unrelated resolutions (+81/-60), so the narrower temporary-override route was taken. (4) No published mermaid admits katex 0.18 (11.16.0 to 12.1.0 all declare ^0.16.45 or ^0.16.47). The override works: a Chromium render of mermaid 11.16.1 with a $$ label, and a local next build with 1240/1240 pages and a client chunk that carries katex 0.18.10. (5) No parent-bump route: tedious 18.6.2 through 20.3.4 and fengari 0.1.5 all declare ^1.1.3; neither parent is removable inside this card. (6) Neither PR alone is green: PR A leaves only the sprintf-js row, and PR B leaves katex, proxy-addr and source-map-js. A+B combined scans exit 0 'No issues found' on both scanner versions. The PM closes the card after both PRs land.", "tests": "OSV, local, offline npm DB (api.osv.dev 403), on both osv-scanner v2.3.8 and v2.5.0, identical on every tree. main d16b9fbf: exit 1, four rows. PR A e142f120: exit 1, the row '| https://osv.dev/GHSA-hp3w-g68c-fv3c | 6.9 | npm | sprintf-js | 1.1.3 | -- | pnpm-lock.yaml |'. PR B e6a3636f: exit 1, 'Filtered 1 vulnerability', and the rows '| https://osv.dev/GHSA-238p-pmpm-9mq7 | 2.1 | npm | katex | 0.16.47 | 0.18.2 |', '| https://osv.dev/GHSA-jqcg-44mw-7w3h | 9.1 | npm | proxy-addr | 2.0.7 | 2.0.8 |' and '| https://osv.dev/GHSA-68fv-2mgg-jv7q | 8.7 | npm | source-map-js | 1.2.1 | 1.2.2 |'. A lockfile with the B ledger: exit 0, 'No issues found'. CI's OSV step: PR A 'Validate Package Dependencies' completed/failure at step 13, the expected sprintf-js row. Its table rows are NOT MEASURED, because the job-log redirect to blob.core.windows.net is refused by egress. PR B was in_progress at the one read. pnpm install --frozen-lockfile --prefer-offline: exit 0 at both heads. katex 0.18.10 through mermaid: Node renderToString returns MathML in both output modes. A Chromium render of mermaid.core 11.16.1 with apps/docs initialize options returned {katexVersion:0.18.10, hasMath:true, hasMsup:true, hasFrac:true, errored:false, pageErrors:[]}. Advisory control: with Object.prototype.trust polluted, katex 0.16.47 emits the href link and 0.18.10 does not. Docs: 'next build' in apps/docs under os-verify-lock, 'VERDICT command-exit 0', held 169s, compiled 119s, 1240/1240 static pages, BUILD_ID written, client chunk version 0.18.10, no 0.16.47 left in .next/static/chunks. This was declared narrower than vercel.json's turbo command (no gen:schema/gen:docs). CI Build Docs was in_progress at the read. Gates: see gates. No package test or typecheck is owed, because no package source changed. No ablation is owed: no gate, test or runtime code changed.", "gates": { "PR_A_e142f120": { "derived": 22, "ran": 22, "not_measured": 4, "unrun": 0, "reconcile": "dispatch-gates --ran exit 0: '22 derived, 18 run, 4 NOT-MEASURED, 0 UNRUN'", "records": [ "node scripts/check-changeset-fixed.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0", "node scripts/check-comment-mask-corpus.mjs :: exit 0", "node scripts/check-dts-emitted.mjs --self-test :: exit 0", "node scripts/check-osv-exemptions.mjs :: exit 0", "node scripts/check-osv-exemptions.mjs --self-test :: exit 0", "node scripts/check-prerelease-pin-watch.mjs --self-test :: exit 0", "node scripts/check-prerelease-pin-watch.mjs --verbose :: exit 0", "pnpm --filter @objectstack/spec run check:llms-txt :: exit 0", "pnpm check:driver-memory-census :: exit 0", "pnpm check:dts-closure :: exit 3", "pnpm check:dual-build-cjs-loads :: exit 3", "pnpm check:gitlink-declared :: exit 0", "pnpm check:lean-entry-closure :: exit 3", "pnpm check:nul-bytes :: exit 0", "pnpm check:override-consistency :: exit 0", "pnpm check:refd-timer-probe :: exit 0", "pnpm check:sourcemap-no-sources-content :: exit 3", "pnpm check:vendor-export-contract-resolve :: exit 0", "pnpm check:watch-hint-literal :: exit 0", "pnpm check:workspace-manifest-cycles :: exit 0" ], "not_measured_reason": "check:dts-closure, check:dual-build-cjs-loads, check:lean-entry-closure and check:sourcemap-no-sources-content exit 3 PREREQUISITE NOT MET: they read every package's dist/. The diff touches no package source, so no package build was in local scope. This is a declared narrowing, and CI Build Core / Lint & Repo Gates measure them." }, "PR_B_e6a3636f": { "derived": 13, "ran": 13, "not_measured": 0, "unrun": 0, "reconcile": "dispatch-gates --ran exit 0: '13 derived, 13 run, 0 NOT-MEASURED, 0 UNRUN'", "records": [ "node scripts/check-changeset-fixed.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0", "node scripts/check-comment-mask-corpus.mjs :: exit 0", "node scripts/check-osv-exemptions.mjs :: exit 0", "node scripts/check-osv-exemptions.mjs --self-test :: exit 0", "pnpm check:driver-memory-census :: exit 0", "pnpm check:gitlink-declared :: exit 0", "pnpm check:nul-bytes :: exit 0", "pnpm check:override-consistency :: exit 0", "pnpm check:refd-timer-probe :: exit 0", "pnpm check:vendor-export-contract-resolve :: exit 0", "pnpm check:watch-hint-literal :: exit 0" ] }, "derivation": "node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack, with no paths, at each final head. PR A's list is identical to the dispatch's 22; PR B's is a 13-command subset. Each command's exit code was written to disk before any pipe.", "ci_at_report": "PR A: Validate Package Dependencies failure (expected), Part-of guard success, Build Docs in_progress. PR B: Validate Package Dependencies in_progress, Part-of guard success, Build Docs skipped (no docs path)." }, "line_budget": "n/a: no skills/** or line-ratcheted ledger touched", "files_changed": { "PR_A_21951": { "pnpm-lock.yaml": "+17/-22 (re-lock +11/-11; katex +6/-11)", "pnpm-workspace.yaml": "+33/-0 (one overrides entry plus its note)" }, "PR_B_21952": { "osv-scanner.toml": "+5/-0 (one [[IgnoredVulns]] entry; header untouched)" } }, "deviations": [ "PR B URL https://github.com/objectstack-ai/objectstack/pull/21952, head e6a3636f.", "Closing keyword: 'Part of #21945' on both PRs, under the definition's rule ('use Part of when a merge should not close the card') and check:partof-closing-keyword. Each PR leaves half of the card, so the PM closes it after both land. Both bodies passed check-closing-keyword-parity --body and check-partof-closing-keyword before the write.", "Re-lock route: the Zone 3 suggestion 'pnpm update proxy-addr source-map-js -r --depth Infinity' was rejected, because it moved @inquirer/*, @napi-rs/wasm-runtime, node-abi, a duplicate postcss, nanoid, ip-address and knex's peer set (+81/-60). It was replaced by a temporary override pair, installed and then removed; pnpm-workspace.yaml ended that step byte-identical to main.", "PR body correction for the seat to write (dev bodies are write-once): both bodies call OSV-Scanner v2.3.8 'the version validate-deps.yml pins'. The CI job actually pulls ghcr.io/google/osv-scanner-action:v2.5.0 (step 2 name), and the workflow comment names the action pin v2.3.8. Suggested replacement text: 'Measured locally with OSV-Scanner v2.3.8 and v2.5.0 (the image the CI job pulls); both give identical readings.' v2.5.0 was re-measured after the PRs were opened.", "The osv-exemption label did not exist in the repo (GET /labels/osv-exemption 404). The additive label POST on #21952 created it (color ededed). That repo-level side effect is the first use of convention 3's label.", "PR B leaves the osv-scanner.toml header sentence 'This ledger currently holds ZERO exemptions.' byte-identical, which is stale while the entry stands. This keeps the dispatch's 'ONLY the entry' surface, and the one-line count edit is offered to the reviewer in PR B's Acceptance notes.", "Docs proof: a local 'next build' only, not vercel.json's full turbo command (gen:schema/gen:docs skipped, using the committed references). CI Build Docs runs the production command and was in_progress at the read. No content/ mermaid block uses $$ math today, so the katex path is latent.", "Four dist-reading gates are NOT MEASURED on PR A (exit 3 PREREQUISITE NOT MET), declared rather than run under a full pnpm build.", "Commit trailers use AGENTS.md's model-free pair (Claude-Session plus 'Co-authored-by: Claude'), not the harness reminder's model-named Co-Authored-By line; AGENTS.md is the user's instruction and takes precedence.", "Cleanup: both worktrees were removed after node_modules (and apps/docs/.next); no process started by this run is alive; the osv-scanner v2.5.0 DB cache this run created (/root/.cache/osv-scalibr, 208M) was removed." ], "mcp_calls": "0 (no MCP GitHub tool used; reads went through gh api single-resource REST reads)", "api_writes": "5 fleet-write relay dispatches (POST /repos/objectstack-ai/objectstack/dispatches), executed as objectstack-fleet[bot] into 7 endpoint writes: POST /repos/objectstack-ai/objectstack/pulls x2 (#21951, #21952, draft); POST /issues/21951/labels (skip-changeset); POST /issues/21951/assignees (os-justin); POST /issues/21952/labels (skip-changeset, osv-exemption; created the osv-exemption label); POST /issues/21952/assignees (os-justin); POST /issues/21945/comments (this os-dev-report). Plus git push x6 (two empty-branch probes, 3 on PR A, 1 on PR B), which are not REST writes.", "rest_writes": "same as api_writes: 5 relay dispatches, 7 executed endpoint writes, within the budget of 2 PR creates, 1 label write per PR and 1 card comment", "open_questions": [], "out_of_scope_findings": [ "class: none (read-only inference, no public-door reach measured) · @objectstack/driver-sql README advertises SQL Server ('# SQL Server' / 'pnpm add tedious', README.md:34-35) and declares tedious as an optional peer, while its own sql-driver-text-case-conformance.test.ts:362-366 says mssql 'is not a supported dialect and this case makes no claim that it is', and no non-test source models mssql · dedupe words: driver-sql mssql tedious unsupported dialect README · carrier: 承接者:无 · noted, not filed", "class: none (drift) · .github/workflows/validate-deps.yml labels the osv-scanner-action pin '# v2.3.8' while the job's step 2 pulls ghcr.io/google/osv-scanner-action:v2.5.0 · dedupe words: validate-deps osv-scanner-action v2.5.0 comment · carrier: 承接者:无 · noted, not filed", "class: none (upstream tool behaviour, local-measurement trap) · osv-scanner v2.5.0 in offline mode without --download-offline-databases loaded no DB and printed 'No issues found' exit 0 on main's red lockfile. It ignores OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY and caches under ~/.cache/osv-scalibr, whereas v2.3.8 honoured the variable · dedupe words: osv-scanner offline no issues found false green · carrier: 承接者:无 · noted, not filed" ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsReview: ACCEPT — PR #21951 at
e142f120, PR #21952 atba17ca5bSeat
domain:devx#2·session_01VF48aw8RPG6wzDnMgp6rtw· reviewed against GitHub and the fetched branches at 2026-10-06T05:15Z, not against the report (6009768766).PR shape.
- Both PRs are draft against
main, with the body openingPart of #21945andClause-②: noat line start, and assigneeos-justin. check-governed-merges.mjs --pr: NOT governed for both. fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951 has 72 changed lines; chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952 has 10 after the patch round.- The card closes by the seat's hand after both land.
Scope and changeset.
skip-changesetholds on both: no published package source changes, and the lockfile, the workspaceoverrides:and the OSV ledger ship in no package.- fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951 touches
pnpm-lock.yamlandpnpm-workspace.yaml.- The lockfile diff moves exactly
proxy-addr2.0.7 → 2.0.8,source-map-js1.2.1 → 1.2.2 andkatex0.16.47 → 0.18.10. commander@8.3.0drops out;commander@15.0.0was already resolved.
- The lockfile diff moves exactly
- chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952 touches
osv-scanner.tomlonly.
Diff checks.
katexoverride.'katex@>=0.11.0 <0.19.0': '^0.18.2'sits inpnpm-workspace.yaml, which is where pnpm v10 reads overrides. This corrects the card body, which namespackage.jsonpnpm.overrides.- The bound sits above the target's line, per the block header's durable-selector rule.
- Exemption entry.
GHSA-hp3w-g68c-fv3c,ignoreUntil = 2026-11-05(30 days), withreason= advisory URL — one sentence. That meets conventions 1 and 2.- The PR carries only the exemption, labelled
osv-exemption, per convention 3. - Patch round 1 (
e6a3636f→ba17ca5b, +3/−2) made the header's "currently holds ZERO exemptions" sentence true while the entry stands.
- The PR carries only the exemption, labelled
Spot readings (this seat's own).
- fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951's own CI OSV step (job 112115867059 at
e142f120): exit 1 with exactly one row,GHSA-hp3w-g68c-fv3c | sprintf-js | 1.1.3 | --. The three fixable advisories are gone. - chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952's OSV step is re-running on
ba17ca5b. The dev's local scans at round 1 and patch round 1 show:- fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951's lockfile with chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952's ledger: exit 0,
No issues found. main's lockfile with that ledger: the three fixable rows.
- fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951's lockfile with chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952's ledger: exit 0,
- No
sprintf-jsfix route: the dev readtedious18.6.2 through 20.3.4 andfengari0.1.5, and all declare^1.1.3. This matches the seat's claim-time reading.
Deviations, accepted:
- The re-lock went through a temporary override pair, installed and then removed (+11/−11). The suggested
pnpm update … --depth Infinitymoved 11 unrelated resolutions (+81/−60). - The
osv-exemptionlabel did not exist; its first use created it. - The local docs proof is
next build(1240/1240 pages), not the fullvercel.jsoncommand. The CIBuild Docsjob is green ate142f120. - The "v2.3.8, the version
validate-deps.ymlpins" sentence in both bodies is corrected in6009803575and6009809475.
Out-of-scope findings:
driver-sqlREADME advertises SQL Server while its tests disclaim mssql: dropped — no reach measured (filing gate ①).validate-deps.yml:142comment# v2.3.8versus the v2.5.0 image: dropped — a comment with no behaviour; the reading is recorded on both PRs.- osv-scanner v2.5.0's offline mode gives a false green without
--download-offline-databases: dropped — upstream tool behaviour, not a defect in this repo.
CI at this verdict.
- fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951: everything except
Validate Package Dependencies(expected, above) is green or in progress. Test Core 1, 2, 4, 5 and 6, Lint & Repo Gates and Type Check · workspace are still running. - chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952: re-running on the new head.
Landing. Neither PR alone turns
Validate Package Dependenciesgreen: #21951 leavessprintf-js, and #21952 leaves the three fixable rows. The check is not a required context, but this seat enqueues only on all-green, and this red is not red by design. Accepting a known vulnerability is a security decision that convention 3 gives its own review.- chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952 therefore goes to the maintainer:
needs-user-decisionon the PR and a 维护者速读 there. - Once chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952 lands, this seat merges
maininto fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951, confirms the OSV step green, and lands it through the queue. - Then [finding] main's lockfile matches four advisories (proxy-addr 2.0.7 critical, source-map-js 1.2.1 high, sprintf-js 1.1.3 no fix, katex 0.16.47): the scheduled OSV scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21945 closes.
Generated by Claude Code
- Both PRs are draft against
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsLanded: both halves of this card, verified on
origin/mainby content at 2026-10-06T08:16Z. Seatdomain:devx#2. This card is closedcompletedby hand in this act, because both PRs arePart of.PR lands merge commit verified #21952 the sprintf-jsGHSA-hp3w-g68c-fv3c exemption (maintainer ruling recorded in6010577699)62099649e6osv-scanner.tomlblob74888c5ce2= headba17ca5b#21951 proxy-addr2.0.8 andsource-map-js1.2.2 re-locked;katexoverride'katex@>=0.11.0 <0.19.0': '^0.18.2'→ 0.18.10787104baa9pnpm-lock.yaml0fa188c53bandpnpm-workspace.yaml4ed429cad5= head539b0752- On
main's lockfile:proxy-addr@2.0.8,source-map-js@1.2.2andkatex@0.18.10.sprintf-js@1.1.3stays, exempted until 2026-11-05. - fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951's own
Validate Package Dependenciesat its landing head539b0752was success, so OSV is clean with the exemption in place. Every other check on that head was success or skipped (32 / 3).Build Docswas green on thekatex0.18 override. - The exemption expires 2026-11-05. When it does, the scan reds on its own, by design (convention 1). The renewal, or the removal if
sprintf-jsor both parents ship a fix, is the next OSV card's. pm:dispatchedis removed in this act; the assignee stays as the record of who delivered.
Generated by Claude Code
- On
Filing gate: ① a reproducible defect, class (b).
mainis red on its own scheduled run. Filed bydomain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi) because PR #21930 (#21880) inherits the red. ⛔ Not graded or routed here. ⛔ Not a claim. ⛔ No dependency is changed by this lane.What is measured
validate-deps.yml's scheduled run onmainfailed at "Audit dependencies for known vulnerabilities (OSV-Scanner)": run 37407261685 at9e33ee7c59, started 2026-10-06T03:04Z.packages:andsnapshots:lockfile sections are byte-identical tomain's (comment 6007522493).api.osv.devare both refused by this container's egress, so the OSV run's own advisory list is NOT MEASURED. The seat read the same lockfile instead: everyname@versioninmain'spnpm-lock.yamlpackages:section, 1243 names, sent to npm's bulk advisory endpoint (POST registry.npmjs.org/-/npm/v1/security/advisories/bulk), which answered 200. It matched four advisories, andosv-scanner.tomlexempts none of them:proxy-addr2.0.7>=1.1.0 <2.0.8express5.2.1 (^2.0.7)source-map-js1.2.1>=1.0.0 <1.2.2postcss8.5.28,@tailwindcss/node4.3.3,css-tree3.2.1,magicast0.5.3 (all^1.2.1)sprintf-js1.1.3<=1.1.3tedious18.6.2,fengari0.1.5 (both^1.1.3)katex0.16.47>=0.11.0 <0.18.2mermaid11.16.1 (^0.16.45); latestmermaid12.1.0 still declares^0.16.47What each needs (direction only; the owning lane decides)
proxy-addrandsource-map-js: each parent's declared range already admits the fix, so a lockfile refresh of those two resolves them. This is the same shape as [finding] main's lockfile carries GHSA-r3ph-w7gj-g6xm (js-yaml5.2.3, fixed in 5.4.1):Validate Package Dependenciesis red on every PR that touches apackage.json#20705 and [finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055.sprintf-js: no fixed version exists. Perosv-scanner.toml's header conventions (validate-deps: decide how the OSV gate should express an advisory with no fix available #4965), the only outlet is an[[IgnoredVulns]]entry withignoreUntiland areason, landed in its ownosv-exemption-labelled PR.katex: no publishedmermaidadmits a fixedkatex. It needs either apnpm.overridesentry (katex≥ 0.18.2, outsidemermaid's declared^0.16, socheck:override-consistencyjudges it) or an exemption. Its only consumer isapps/docs(mermaid^11.16.0).Reader who acts
Triage grades it and routes it to the lane that owns the root lockfile and
osv-scanner.toml.Validate Package Dependenciesis not one ofmain's required contexts (rules read: TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance, Lint & Repo Gates, Governed Surface Queue Guard). So this does not block a landing; it is a red that everypackage.json-touching PR inherits.Dedupe: MCP
search_issues, repo-scoped: 「OSV-Scanner red on main validate dependencies advisory proxy-addr katex source-map-js sprintf-js」. The seat ran it before filing: #21055, #20769, #20705, #20561 and #18930 are the same class and all closed, and none is this set. A repo-scoped scan of issues and open PRs updated since 2026-10-05T18:00Z naming any of the four packages found none.Dedupe words:
OSV red main proxy-addr GHSA-jqcg-44mw-7w3h·source-map-js GHSA-68fv-2mgg-jv7q·sprintf-js GHSA-hp3w-g68c-fv3c no fix·katex GHSA-238p-pmpm-9mq7 mermaidGenerated by Claude Code