Skip to content

[finding] main's lockfile matches four advisories (proxy-addr 2.0.7 critical, source-map-js 1.2.1 high, sprintf-js 1.1.3 no fix, katex 0.16.47): the scheduled OSV scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21945

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (b). main is red on its own scheduled run. Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) because PR #21930 (#21880) inherits the red. ⛔ Not graded or routed here. ⛔ Not a claim. ⛔ No dependency is changed by this lane.

What is measured

  • The red runs. validate-deps.yml's scheduled run on main failed at "Audit dependencies for known vulnerabilities (OSV-Scanner)": run 37407261685 at 9e33ee7c59, started 2026-10-06T03:04Z.
  • The advisory set. The job log and api.osv.dev are both refused by this container's egress, so the OSV run's own advisory list is NOT MEASURED. The seat read the same lockfile instead: every name@version in main's pnpm-lock.yaml packages: section, 1243 names, sent to npm's bulk advisory endpoint (POST registry.npmjs.org/-/npm/v1/security/advisories/bulk), which answered 200. It matched four advisories, and osv-scanner.toml exempts none of them:
package @ locked advisory severity vulnerable fix pulled in by (declared range)
proxy-addr 2.0.7 GHSA-jqcg-44mw-7w3h (IP spoofing via an IPv4-mapped IPv6 trust subnet) critical >=1.1.0 <2.0.8 2.0.8, published 2026-09-15 express 5.2.1 (^2.0.7)
source-map-js 1.2.1 GHSA-68fv-2mgg-jv7q (event-loop DoS through indexed source-map section offsets) high >=1.0.0 <1.2.2 1.2.2, published 2026-09-30 postcss 8.5.28, @tailwindcss/node 4.3.3, css-tree 3.2.1, magicast 0.5.3 (all ^1.2.1)
sprintf-js 1.1.3 GHSA-hp3w-g68c-fv3c (DoS through unbounded precision specifiers) moderate <=1.1.3 none: 1.1.3 is the latest published version tedious 18.6.2, fengari 0.1.5 (both ^1.1.3)
katex 0.16.47 GHSA-238p-pmpm-9mq7 (existing prototype pollution can bypass trust restrictions) low >=0.11.0 <0.18.2 0.18.2+ (latest 0.19.0) mermaid 11.16.1 (^0.16.45); latest mermaid 12.1.0 still declares ^0.16.47

What each needs (direction only; the owning lane decides)

Reader who acts

Triage grades it and routes it to the lane that owns the root lockfile and osv-scanner.toml. Validate Package Dependencies is not one of main's required contexts (rules read: TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance, Lint & Repo Gates, Governed Surface Queue Guard). So this does not block a landing; it is a red that every package.json-touching PR inherits.

Dedupe: MCP search_issues, repo-scoped: 「OSV-Scanner red on main validate dependencies advisory proxy-addr katex source-map-js sprintf-js」. The seat ran it before filing: #21055, #20769, #20705, #20561 and #18930 are the same class and all closed, and none is this set. A repo-scoped scan of issues and open PRs updated since 2026-10-05T18:00Z naming any of the four packages found none.

Dedupe words: OSV red main proxy-addr GHSA-jqcg-44mw-7w3h · source-map-js GHSA-68fv-2mgg-jv7q · sprintf-js GHSA-hp3w-g68c-fv3c no fix · katex GHSA-238p-pmpm-9mq7 mermaid


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Path: fleet decision — dependencies carry no known advisory unexempted (validate-deps.yml, osv-scanner.toml #4965) | 缺项 | none

    Triage: first grade — bug · security · priority:p1 · domain:devx · area:devpath · pm:queue (finding removed). It is release-linked: the version PR touches every package.json, so it would go red on this same step

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-06T03:54Z. ⛔ Not a claim, ⛔ not a dispatch.

    Triage: lands in the root pnpm-lock.yaml, osv-scanner.toml and, for katex, package.json pnpm.overrides ⇒ domain:devx; rationale: these are the same files, and the same lane, as #20705 and #21055 (both closed p1, the same shape).


    Generated by Claude Code

  2. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 1
    Session: session_01VF48aw8RPG6wzDnMgp6rtw
    Account: os-justin (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-21945-osv-lockfile-fixes (cut from origin/main at dispatch)
    Worktree: objectstack-issue-21945
    Domain: domain:devx
    Seat: domain:devx#2
    File surface:

    OSV's own list, read this act: the scheduled run 37407261685 (job 112087469784) names exactly the card's four advisories:

    • katex 0.16.47 → 0.18.2
    • proxy-addr 2.0.7 → 2.0.8
    • source-map-js 1.2.1 → 1.2.2
    • sprintf-js 1.1.3 → -- (no fix)

    sprintf-js has no parent-bump route. The latest tedious (20.3.3) and the latest fengari (0.1.5) both still declare sprintf-js ^1.1.3 (npm view, this act). So the exemption is the only outlet.

    Priority rule 3: this is the lane's open P1.


    Generated by Claude Code

  3. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 21945,
      "status": "done",
      "branch": "claude/issue-21945-osv-lockfile-fixes",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/21951",
      "session": "session_01VF48aw8RPG6wzDnMgp6rtw (mode:subagent; this is the dispatching PM's id, and the identity bit is the branch named in claim 6009368904)",
      "premise_still_valid": true,
      "summary": "Two draft PRs, both 'Part of #21945'. PR A, #21951 (head e142f120): proxy-addr 2.0.7 to 2.0.8 and source-map-js 1.2.1 to 1.2.2, re-locked through a temporary override pair that was installed and then removed (+11/-11, two packages only), plus the katex override 'katex@>=0.11.0 <0.19.0': '^0.18.2' with its note, in pnpm-workspace.yaml (which resolves to 0.18.10; npm deprecates 0.18.11). PR B, https://github.com/objectstack-ai/objectstack/pull/21952 (head e6a3636f): only the osv-scanner.toml [[IgnoredVulns]] entry for GHSA-hp3w-g68c-fv3c, ignoreUntil = 2026-11-05 as a bare date, a reason in the convention-2 format, labels osv-exemption and skip-changeset. Its body has the 'Exemption decision' section, answered from code with file:line references. Zone 2 premises, each re-measured: (1) at d16b9fbf the OSV set is exactly the four rows, on osv-scanner v2.3.8 AND v2.5.0 (offline DB; api.osv.dev answers 403). (2) Overrides live in pnpm-workspace.yaml; the root package.json pnpm field holds only ignoredBuiltDependencies. (3) Every parent's range admits the fix, but the suggested 'pnpm update ... -r --depth Infinity' dragged 11 unrelated resolutions (+81/-60), so the narrower temporary-override route was taken. (4) No published mermaid admits katex 0.18 (11.16.0 to 12.1.0 all declare ^0.16.45 or ^0.16.47). The override works: a Chromium render of mermaid 11.16.1 with a $$ label, and a local next build with 1240/1240 pages and a client chunk that carries katex 0.18.10. (5) No parent-bump route: tedious 18.6.2 through 20.3.4 and fengari 0.1.5 all declare ^1.1.3; neither parent is removable inside this card. (6) Neither PR alone is green: PR A leaves only the sprintf-js row, and PR B leaves katex, proxy-addr and source-map-js. A+B combined scans exit 0 'No issues found' on both scanner versions. The PM closes the card after both PRs land.",
      "tests": "OSV, local, offline npm DB (api.osv.dev 403), on both osv-scanner v2.3.8 and v2.5.0, identical on every tree. main d16b9fbf: exit 1, four rows. PR A e142f120: exit 1, the row '| https://osv.dev/GHSA-hp3w-g68c-fv3c | 6.9 | npm | sprintf-js | 1.1.3 | -- | pnpm-lock.yaml |'. PR B e6a3636f: exit 1, 'Filtered 1 vulnerability', and the rows '| https://osv.dev/GHSA-238p-pmpm-9mq7 | 2.1 | npm | katex | 0.16.47 | 0.18.2 |', '| https://osv.dev/GHSA-jqcg-44mw-7w3h | 9.1 | npm | proxy-addr | 2.0.7 | 2.0.8 |' and '| https://osv.dev/GHSA-68fv-2mgg-jv7q | 8.7 | npm | source-map-js | 1.2.1 | 1.2.2 |'. A lockfile with the B ledger: exit 0, 'No issues found'. CI's OSV step: PR A 'Validate Package Dependencies' completed/failure at step 13, the expected sprintf-js row. Its table rows are NOT MEASURED, because the job-log redirect to blob.core.windows.net is refused by egress. PR B was in_progress at the one read. pnpm install --frozen-lockfile --prefer-offline: exit 0 at both heads. katex 0.18.10 through mermaid: Node renderToString returns MathML in both output modes. A Chromium render of mermaid.core 11.16.1 with apps/docs initialize options returned {katexVersion:0.18.10, hasMath:true, hasMsup:true, hasFrac:true, errored:false, pageErrors:[]}. Advisory control: with Object.prototype.trust polluted, katex 0.16.47 emits the href link and 0.18.10 does not. Docs: 'next build' in apps/docs under os-verify-lock, 'VERDICT command-exit 0', held 169s, compiled 119s, 1240/1240 static pages, BUILD_ID written, client chunk version 0.18.10, no 0.16.47 left in .next/static/chunks. This was declared narrower than vercel.json's turbo command (no gen:schema/gen:docs). CI Build Docs was in_progress at the read. Gates: see gates. No package test or typecheck is owed, because no package source changed. No ablation is owed: no gate, test or runtime code changed.",
      "gates": {
        "PR_A_e142f120": {
          "derived": 22,
          "ran": 22,
          "not_measured": 4,
          "unrun": 0,
          "reconcile": "dispatch-gates --ran exit 0: '22 derived, 18 run, 4 NOT-MEASURED, 0 UNRUN'",
          "records": [
            "node scripts/check-changeset-fixed.mjs :: exit 0",
            "node scripts/check-closing-keyword-parity.mjs :: exit 0",
            "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0",
            "node scripts/check-comment-mask-corpus.mjs :: exit 0",
            "node scripts/check-dts-emitted.mjs --self-test :: exit 0",
            "node scripts/check-osv-exemptions.mjs :: exit 0",
            "node scripts/check-osv-exemptions.mjs --self-test :: exit 0",
            "node scripts/check-prerelease-pin-watch.mjs --self-test :: exit 0",
            "node scripts/check-prerelease-pin-watch.mjs --verbose :: exit 0",
            "pnpm --filter @objectstack/spec run check:llms-txt :: exit 0",
            "pnpm check:driver-memory-census :: exit 0",
            "pnpm check:dts-closure :: exit 3",
            "pnpm check:dual-build-cjs-loads :: exit 3",
            "pnpm check:gitlink-declared :: exit 0",
            "pnpm check:lean-entry-closure :: exit 3",
            "pnpm check:nul-bytes :: exit 0",
            "pnpm check:override-consistency :: exit 0",
            "pnpm check:refd-timer-probe :: exit 0",
            "pnpm check:sourcemap-no-sources-content :: exit 3",
            "pnpm check:vendor-export-contract-resolve :: exit 0",
            "pnpm check:watch-hint-literal :: exit 0",
            "pnpm check:workspace-manifest-cycles :: exit 0"
          ],
          "not_measured_reason": "check:dts-closure, check:dual-build-cjs-loads, check:lean-entry-closure and check:sourcemap-no-sources-content exit 3 PREREQUISITE NOT MET: they read every package's dist/. The diff touches no package source, so no package build was in local scope. This is a declared narrowing, and CI Build Core / Lint & Repo Gates measure them."
        },
        "PR_B_e6a3636f": {
          "derived": 13,
          "ran": 13,
          "not_measured": 0,
          "unrun": 0,
          "reconcile": "dispatch-gates --ran exit 0: '13 derived, 13 run, 0 NOT-MEASURED, 0 UNRUN'",
          "records": [
            "node scripts/check-changeset-fixed.mjs :: exit 0",
            "node scripts/check-closing-keyword-parity.mjs :: exit 0",
            "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0",
            "node scripts/check-comment-mask-corpus.mjs :: exit 0",
            "node scripts/check-osv-exemptions.mjs :: exit 0",
            "node scripts/check-osv-exemptions.mjs --self-test :: exit 0",
            "pnpm check:driver-memory-census :: exit 0",
            "pnpm check:gitlink-declared :: exit 0",
            "pnpm check:nul-bytes :: exit 0",
            "pnpm check:override-consistency :: exit 0",
            "pnpm check:refd-timer-probe :: exit 0",
            "pnpm check:vendor-export-contract-resolve :: exit 0",
            "pnpm check:watch-hint-literal :: exit 0"
          ]
        },
        "derivation": "node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack, with no paths, at each final head. PR A's list is identical to the dispatch's 22; PR B's is a 13-command subset. Each command's exit code was written to disk before any pipe.",
        "ci_at_report": "PR A: Validate Package Dependencies failure (expected), Part-of guard success, Build Docs in_progress. PR B: Validate Package Dependencies in_progress, Part-of guard success, Build Docs skipped (no docs path)."
      },
      "line_budget": "n/a: no skills/** or line-ratcheted ledger touched",
      "files_changed": {
        "PR_A_21951": {
          "pnpm-lock.yaml": "+17/-22 (re-lock +11/-11; katex +6/-11)",
          "pnpm-workspace.yaml": "+33/-0 (one overrides entry plus its note)"
        },
        "PR_B_21952": {
          "osv-scanner.toml": "+5/-0 (one [[IgnoredVulns]] entry; header untouched)"
        }
      },
      "deviations": [
        "PR B URL https://github.com/objectstack-ai/objectstack/pull/21952, head e6a3636f.",
        "Closing keyword: 'Part of #21945' on both PRs, under the definition's rule ('use Part of when a merge should not close the card') and check:partof-closing-keyword. Each PR leaves half of the card, so the PM closes it after both land. Both bodies passed check-closing-keyword-parity --body and check-partof-closing-keyword before the write.",
        "Re-lock route: the Zone 3 suggestion 'pnpm update proxy-addr source-map-js -r --depth Infinity' was rejected, because it moved @inquirer/*, @napi-rs/wasm-runtime, node-abi, a duplicate postcss, nanoid, ip-address and knex's peer set (+81/-60). It was replaced by a temporary override pair, installed and then removed; pnpm-workspace.yaml ended that step byte-identical to main.",
        "PR body correction for the seat to write (dev bodies are write-once): both bodies call OSV-Scanner v2.3.8 'the version validate-deps.yml pins'. The CI job actually pulls ghcr.io/google/osv-scanner-action:v2.5.0 (step 2 name), and the workflow comment names the action pin v2.3.8. Suggested replacement text: 'Measured locally with OSV-Scanner v2.3.8 and v2.5.0 (the image the CI job pulls); both give identical readings.' v2.5.0 was re-measured after the PRs were opened.",
        "The osv-exemption label did not exist in the repo (GET /labels/osv-exemption 404). The additive label POST on #21952 created it (color ededed). That repo-level side effect is the first use of convention 3's label.",
        "PR B leaves the osv-scanner.toml header sentence 'This ledger currently holds ZERO exemptions.' byte-identical, which is stale while the entry stands. This keeps the dispatch's 'ONLY the entry' surface, and the one-line count edit is offered to the reviewer in PR B's Acceptance notes.",
        "Docs proof: a local 'next build' only, not vercel.json's full turbo command (gen:schema/gen:docs skipped, using the committed references). CI Build Docs runs the production command and was in_progress at the read. No content/ mermaid block uses $$ math today, so the katex path is latent.",
        "Four dist-reading gates are NOT MEASURED on PR A (exit 3 PREREQUISITE NOT MET), declared rather than run under a full pnpm build.",
        "Commit trailers use AGENTS.md's model-free pair (Claude-Session plus 'Co-authored-by: Claude'), not the harness reminder's model-named Co-Authored-By line; AGENTS.md is the user's instruction and takes precedence.",
        "Cleanup: both worktrees were removed after node_modules (and apps/docs/.next); no process started by this run is alive; the osv-scanner v2.5.0 DB cache this run created (/root/.cache/osv-scalibr, 208M) was removed."
      ],
      "mcp_calls": "0 (no MCP GitHub tool used; reads went through gh api single-resource REST reads)",
      "api_writes": "5 fleet-write relay dispatches (POST /repos/objectstack-ai/objectstack/dispatches), executed as objectstack-fleet[bot] into 7 endpoint writes: POST /repos/objectstack-ai/objectstack/pulls x2 (#21951, #21952, draft); POST /issues/21951/labels (skip-changeset); POST /issues/21951/assignees (os-justin); POST /issues/21952/labels (skip-changeset, osv-exemption; created the osv-exemption label); POST /issues/21952/assignees (os-justin); POST /issues/21945/comments (this os-dev-report). Plus git push x6 (two empty-branch probes, 3 on PR A, 1 on PR B), which are not REST writes.",
      "rest_writes": "same as api_writes: 5 relay dispatches, 7 executed endpoint writes, within the budget of 2 PR creates, 1 label write per PR and 1 card comment",
      "open_questions": [],
      "out_of_scope_findings": [
        "class: none (read-only inference, no public-door reach measured) · @objectstack/driver-sql README advertises SQL Server ('# SQL Server' / 'pnpm add tedious', README.md:34-35) and declares tedious as an optional peer, while its own sql-driver-text-case-conformance.test.ts:362-366 says mssql 'is not a supported dialect and this case makes no claim that it is', and no non-test source models mssql · dedupe words: driver-sql mssql tedious unsupported dialect README · carrier: 承接者:无 · noted, not filed",
        "class: none (drift) · .github/workflows/validate-deps.yml labels the osv-scanner-action pin '# v2.3.8' while the job's step 2 pulls ghcr.io/google/osv-scanner-action:v2.5.0 · dedupe words: validate-deps osv-scanner-action v2.5.0 comment · carrier: 承接者:无 · noted, not filed",
        "class: none (upstream tool behaviour, local-measurement trap) · osv-scanner v2.5.0 in offline mode without --download-offline-databases loaded no DB and printed 'No issues found' exit 0 on main's red lockfile. It ignores OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY and caches under ~/.cache/osv-scalibr, whereas v2.3.8 honoured the variable · dedupe words: osv-scanner offline no issues found false green · carrier: 承接者:无 · noted, not filed"
      ]
    }

    Generated by Claude Code

  4. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Review: ACCEPT — PR #21951 at e142f120, PR #21952 at ba17ca5b

    Seat domain:devx#2 · session_01VF48aw8RPG6wzDnMgp6rtw · reviewed against GitHub and the fetched branches at 2026-10-06T05:15Z, not against the report (6009768766).

    PR shape.

    Scope and changeset. skip-changeset holds on both: no published package source changes, and the lockfile, the workspace overrides: and the OSV ledger ship in no package.

    Diff checks.

    • katex override. 'katex@>=0.11.0 <0.19.0': '^0.18.2' sits in pnpm-workspace.yaml, which is where pnpm v10 reads overrides. This corrects the card body, which names package.json pnpm.overrides.
      • The bound sits above the target's line, per the block header's durable-selector rule.
    • Exemption entry. GHSA-hp3w-g68c-fv3c, ignoreUntil = 2026-11-05 (30 days), with reason = advisory URL — one sentence. That meets conventions 1 and 2.
      • The PR carries only the exemption, labelled osv-exemption, per convention 3.
      • Patch round 1 (e6a3636f → ba17ca5b, +3/−2) made the header's "currently holds ZERO exemptions" sentence true while the entry stands.

    Spot readings (this seat's own).

    Deviations, accepted:

    • The re-lock went through a temporary override pair, installed and then removed (+11/−11). The suggested pnpm update … --depth Infinity moved 11 unrelated resolutions (+81/−60).
    • The osv-exemption label did not exist; its first use created it.
    • The local docs proof is next build (1240/1240 pages), not the full vercel.json command. The CI Build Docs job is green at e142f120.
    • The "v2.3.8, the version validate-deps.yml pins" sentence in both bodies is corrected in 6009803575 and 6009809475.

    Out-of-scope findings:

    • driver-sql README advertises SQL Server while its tests disclaim mssql: dropped — no reach measured (filing gate ①).
    • validate-deps.yml:142 comment # v2.3.8 versus the v2.5.0 image: dropped — a comment with no behaviour; the reading is recorded on both PRs.
    • osv-scanner v2.5.0's offline mode gives a false green without --download-offline-databases: dropped — upstream tool behaviour, not a defect in this repo.

    CI at this verdict.

    Landing. Neither PR alone turns Validate Package Dependencies green: #21951 leaves sprintf-js, and #21952 leaves the three fixable rows. The check is not a required context, but this seat enqueues only on all-green, and this red is not red by design. Accepting a known vulnerability is a security decision that convention 3 gives its own review.

    1. chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952 therefore goes to the maintainer: needs-user-decision on the PR and a 维护者速读 there.
    2. Once chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05 (no fixed release exists) #21952 lands, this seat merges main into fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951, confirms the OSV step green, and lands it through the queue.
    3. Then [finding] main's lockfile matches four advisories (proxy-addr 2.0.7 critical, source-map-js 1.2.1 high, sprintf-js 1.1.3 no fix, katex 0.16.47): the scheduled OSV scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21945 closes.

    Generated by Claude Code

  5. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: both halves of this card, verified on origin/main by content at 2026-10-06T08:16Z. Seat domain:devx#2. This card is closed completed by hand in this act, because both PRs are Part of.

    PR lands merge commit verified
    #21952 the sprintf-js GHSA-hp3w-g68c-fv3c exemption (maintainer ruling recorded in 6010577699) 62099649e6 osv-scanner.toml blob 74888c5ce2 = head ba17ca5b
    #21951 proxy-addr 2.0.8 and source-map-js 1.2.2 re-locked; katex override 'katex@>=0.11.0 <0.19.0': '^0.18.2' → 0.18.10 787104baa9 pnpm-lock.yaml 0fa188c53b and pnpm-workspace.yaml 4ed429cad5 = head 539b0752
    • On main's lockfile: proxy-addr@2.0.8, source-map-js@1.2.2 and katex@0.18.10. sprintf-js@1.1.3 stays, exempted until 2026-11-05.
    • fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red #21951's own Validate Package Dependencies at its landing head 539b0752 was success, so OSV is clean with the exemption in place. Every other check on that head was success or skipped (32 / 3). Build Docs was green on the katex 0.18 override.
    • The exemption expires 2026-11-05. When it does, the scan reds on its own, by design (convention 1). The renewal, or the removal if sprintf-js or both parents ship a fix, is the next OSV card's.
    • pm:dispatched is removed in this act; the assignee stays as the record of who delivered.

    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxpriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions