Repository navigation
fix(deps): move next 16.3.6 to 16.3.8, clearing six OSV advisories on main's lockfile - #22181
Merged
Merged
Conversation
…ix OSV advisories apps/docs pins next exactly; better-auth's optional next peer resolved to the same version. Both resolutions now name 16.3.8. The lockfile change is regenerated by pnpm and moves only next, @next/env and the eight @next/swc-* binaries. Advisories fixed in 16.3.8 (OSV ranges, fixed: 16.3.8): GHSA-mcj8-r9mp-w47p, GHSA-f87g-xv8r-7p7x, GHSA-cjq9-62q9-8jv4, GHSA-4jqv-mc3x-m676, GHSA-3w37-wq28-93x7, GHSA-39w2-rjm5-chcv. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #22148
Clause-②: no
What this does
Moves every
nextresolution in the lockfile from16.3.6to16.3.8. That patch release is the fixed version of all six OSV advisories thatmain's scheduledValidate Package Dependenciesscan is red on.apps/docs/package.json: the exact pin"next": "16.3.6"becomes"next": "16.3.8". It is the onlynextdeclarer in the workspace.pnpm-lock.yaml: regenerated bypnpm install, not edited by hand.better-auth@1.7.3takesnextas an optional peer, and pnpm resolved it to the same version as the docs pin. Its resolution follows to16.3.8with no change topackages/plugins/plugin-auth/package.json.overrides:entry, no exemption, no edit tovalidate-deps.yml,osv-scanner.tomlorscripts/osv-base-relative.mjs.@objectstack/docsisprivate, and no published package's manifest orfiles[]content changes, so this PR is labelledskip-changeset.The fixed versions, read before choosing
Read from the OSV export bucket (
storage.googleapis.com/osv-vulnerabilities/npm/ID.json). All six records were published 2026-10-07 and modified 2026-10-07T20:45Z.Every one of the six has a fixed release, so no exemption is needed.
Why 16.3.8 and not 16.4.0 (
latest): 16.3.8 is the smallest move that fixes all six. It is a patch inside the line already pinned, published 2026-09-30. Everynextpeer range in the tree accepts it:fumadocs-core@16.14.4andfumadocs-ui@16.14.4(16.x.x),fumadocs-mdx@15.2.3(^15.3.0 || ^16.0.0),better-auth@1.7.3(^14.0.0 || ^15.0.0 || ^16.0.0).Evidence (head
b6e4c2caca, merge base959c209d56)Lockfile.
grep -c 'next@16.3.6' pnpm-lock.yamlreturns0at the head (it was 22 at the base).next@resolution in the lockfile names16.3.8(26 occurrences). Nonext@resolution of any other version remains.16.3.6and16.3.8are normalised, apart from 10integrityhashes:next,@next/envand the eight@next/swc-*binaries.pnpm install --frozen-lockfileexits 0 ("Already up to date").OSV, scanned locally with the same scanner version the workflow pins:
osv-scannerv2.5.0, the release binary, whose sha256 matches the release'sSHA256SUMS. It used an offline npm database freshly downloaded from the OSV bucket at 2026-10-08T04:13Z. Both scans load each side's ownosv-scanner.toml, as the workflow does.959c209d56: exit 1, six findings, all onnext@16.3.6. Those are the six above, and they serve as the positive control.b6e4c2caca: exit 0, zero findings. The ledger's one exemption (GHSA-hp3w-g68c-fv3c, sprintf-js) is still applied on both sides.scripts/osv-base-relative.mjs. It printed:OSV base-relative verdict against the merge base (959c209d56a8): 0 introduced, 0 inherited, 6 resolved.--download-offline-databases, it loaded no database and returned zero findings with exit 0, even for the base lockfile. So each leg above was checked for itsLoaded npm local dbline, and the base leg's six findings show the database was really loaded.validate-deps.ymlrun is37727268306, job113148187921, at headb6e4c2caca:OSV base-relative verdict against the merge base (959c209d56a8): 0 introduced, 0 inherited, 6 resolved.(Seat amendment: the run existed only after the PR was opened.)The docs site builds with the new
next. I ran the production build command read fromapps/docs/vercel.json(pnpm turbo run build --filter=@objectstack/docs) withTURBO_FORCE=true, as theBuild Docsjob does.▲ Next.js 16.3.8 (Turbopack)·✓ Compiled successfully in 90s·✓ Generating static pages using 2 workers (1243/1243).apps/docs/.next/BUILD_IDis present.pnpm --filter @objectstack/docs run typecheck(fumadocs-mdx && next typegen && tsc --noEmit) exits 0.Gates. I derived them from this worktree with
node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackatb6e4c2caca, which gave the same 41 commands as at dispatch, and ran all 41.--ran:41 derived famil(ies) accounted for — 39 run, 2 NOT-MEASURED (2 DERIVED from a recorded exit 3).check-osv-exemptionsand its self-test,osv-base-relative --self-test,check:override-consistency,check:vendor-export-contract-resolve,check:nul-bytesandcheck:published-files.pnpm check:dual-build-cjs-loadsandpnpm check:lean-entry-closureboth exit 3, PREREQUISITE NOT MET. They load built entry points of the whole workspace, and only the docs build closure (@objectstack/spec) was built here. CI's full build measures them. This diff changes no package's source, build config orexports.check:dts-closureandcheck:sourcemap-no-sources-contentswept the one built package (@objectstack/spec).filesglobs are JS/TS only. Type-aware linting is not enabled (noparserOptions.project), so this diff cannot move any untouched file's verdict.Acceptance notes
Generated by Claude Code