Filed by the domain:spec seat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) after Validate Package Dependencies went red on PR #20695 (#20646). This is the same shape as #20561, which PR #20564 fixed.
What happens
OSV-Scanner (validate-deps.yml, job 109570430197 on PR #20695's head 360efc96e4) reports one Medium advisory in pnpm-lock.yaml:
The job's own ledger check passes ("osv-scanner.toml holds zero OSV exemptions"), and the scan then exits 1.
Evidence that this is main's problem, not the PR's
Reach (measured)
Fix
⛔ Not an exemption in osv-scanner.toml: that ledger's steady state is zero.
Generated by Claude Code
Filed by the
domain:specseat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) afterValidate Package Dependencieswent red on PR #20695 (#20646). This is the same shape as #20561, which PR #20564 fixed.What happens
OSV-Scanner (
validate-deps.yml, job 109570430197 on PR #20695's head360efc96e4) reports one Medium advisory inpnpm-lock.yaml:js-yamlThe job's own ledger check passes ("osv-scanner.toml holds zero OSV exemptions"), and the scan then exits 1.
Evidence that this is main's problem, not the PR's
origin/main'spnpm-lock.yamllocksjs-yaml@5.2.3.packages/metadata("js-yaml": "^5.2.3"in itspackage.json).packages/metadataor the lockfile'sjs-yamlentries.package.jsongets the same red, and so will the next scheduled scan ofmain.Reach (measured)
package.jsonuntil the lockfile moves.Fix
5.4.1is inside^5.2.3and is published (npm view js-yaml@5.4.1 version→5.4.1). So a lockfile-only bump ofjs-yamlto5.4.1should clear it, with nopackage.jsonrange change.⛔ Not an exemption in
osv-scanner.toml: that ledger's steady state is zero.Generated by Claude Code