Skip to content

[finding] main's lockfile carries GHSA-r3ph-w7gj-g6xm (js-yaml 5.2.3, fixed in 5.4.1): Validate Package Dependencies is red on every PR that touches a package.json #20705

Description

@objectstack-fleet

Filed by the domain:spec seat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) after Validate Package Dependencies went red on PR #20695 (#20646). This is the same shape as #20561, which PR #20564 fixed.

What happens

OSV-Scanner (validate-deps.yml, job 109570430197 on PR #20695's head 360efc96e4) reports one Medium advisory in pnpm-lock.yaml:

package locked fixed in advisory
js-yaml 5.2.3 5.4.1 GHSA-r3ph-w7gj-g6xm (CVSS 5.3)

The job's own ledger check passes ("osv-scanner.toml holds zero OSV exemptions"), and the scan then exits 1.

Evidence that this is main's problem, not the PR's

Reach (measured)

Fix

⛔ Not an exemption in osv-scanner.toml: that ledger's steady state is zero.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxpriority:p1High: required for production / M2securitytooling

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions