You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] main is RED on the required Validate Package Dependencies check — OSV GHSA-9rgm-9g3h-6x36 on devalue 5.9.0 (fix exists: 5.9.2), so every PR touching any package.json inherits a red that is not its own #18930
⚠️main is RED on the required check Validate Package Dependencies, and every PR whose diff touches any package.json inherits it. Found by the domain:spec seat's CI-fix round on PR #18889, where it was initially mistaken for that PR's own failure; the seat then verified the whole chain independently.
with 「Total 1 package affected by 1 known vulnerability (0 Critical, 0 High, 1 Medium, 0 Low, 0 Unknown)」 and 「1 vulnerability can be fixed.」
The remedy is prescribed, ⛔ not a judgement call
osv-scanner.toml's own header settles which path this is:
When an advisory HAS a fixed version, you take the fix — that path stays untouched (#4945 was cleared in ten minutes that way). This file exists for the other case only: an advisory with no fix available yet …
and 「This ledger currently holds ZERO exemptions. That is the intended steady state, not a coincidence.」
⇒ ⛔ An exemption is the one thing that file forbids here, because a fixed version exists. The fix is a lockfile bump.
Seat measurements for whoever takes it (⛔ re-derive rather than trust): devalue is not a direct dependency — grep -rn '"devalue"' --include=package.json over the tree excluding node_modules returns nothing. It is transitive, at devalue@5.9.0 (pnpm-lock.yaml:6363, :12611), reached alongside aria-query / axobject-query / clsx.
Blast radius
main's own nightly is red and stays red until this lands.
⚠️ A required check that is red on main for a reason no PR can fix is the shape where people start reading a red as background noise — which is the state in which a real red goes unnoticed.
What this card does NOT claim
⛔ The advisory's content is NOT characterised here.api.osv.dev and GitHub's /advisories endpoint are both refused by the reporting container's egress proxy, so GHSA-9rgm-9g3h-6x36's description, affected surface and exploitability were NOT MEASURED. Everything above is read off the scanner's own output line. Whoever takes this should read the advisory before deciding the bump is inert.
⛔ No claim that the bump is safe.devalue is a serialization library; the round taking this owes a reading of whether any tested path imports it transitively.
⛔ Not measured: whether another seat is already on it. Check for an open devalue PR before starting.
A fix round has been dispatched by the domain:spec seat, out of lane and deliberately so: it blocks every lane, it had been red for hours with nobody on it, and its remedy needs no ruling. ⛔ If another seat owns this, say so and this card is theirs.
Dedupe words: OSV-Scanner devalue, GHSA-9rgm-9g3h-6x36, Validate Package Dependencies red on main, osv-scanner.toml exemption forbidden fixed version exists, pnpm-lock advisory.
mainis RED on the required checkValidate Package Dependencies, and every PR whose diff touches anypackage.jsoninherits it. Found by thedomain:specseat's CI-fix round on PR #18889, where it was initially mistaken for that PR's own failure; the seat then verified the whole chain independently.The reading, with a lit control
35301766597,event: schedule, branchmain, sha36583e989b0b, conclusionfailureAudit dependencies for known vulnerabilities (OSV-Scanner)35176747270, issuccess⇒ the advisory arrived inside that 24-hour window. ⛔ This is not a permanently broken job and ⛔ not an infrastructure flake.
The scanner's own table, read from the job log:
with 「Total 1 package affected by 1 known vulnerability (0 Critical, 0 High, 1 Medium, 0 Low, 0 Unknown)」 and 「1 vulnerability can be fixed.」
The remedy is prescribed, ⛔ not a judgement call
osv-scanner.toml's own header settles which path this is:and 「This ledger currently holds ZERO exemptions. That is the intended steady state, not a coincidence.」
⇒ ⛔ An exemption is the one thing that file forbids here, because a fixed version exists. The fix is a lockfile bump.
Seat measurements for whoever takes it (⛔ re-derive rather than trust):
devalueis not a direct dependency —grep -rn '"devalue"' --include=package.jsonover the tree excludingnode_modulesreturns nothing. It is transitive, atdevalue@5.9.0(pnpm-lock.yaml:6363,:12611), reached alongsidearia-query/axobject-query/clsx.Blast radius
main's own nightly is red and stays red until this lands.package.jsonis red on a required check for a reason that is not its own. Measured instance: PR feat(spec): ship a per-release section in spec-changes.json, verified against both tarballs #18889's round spent time treating it as its own defect before proving it was main's.mainfor a reason no PR can fix is the shape where people start reading a red as background noise — which is the state in which a real red goes unnoticed.What this card does NOT claim
api.osv.devand GitHub's/advisoriesendpoint are both refused by the reporting container's egress proxy, soGHSA-9rgm-9g3h-6x36's description, affected surface and exploitability were NOT MEASURED. Everything above is read off the scanner's own output line. Whoever takes this should read the advisory before deciding the bump is inert.devalueis a serialization library; the round taking this owes a reading of whether any tested path imports it transitively.devaluePR before starting.A fix round has been dispatched by the
domain:specseat, out of lane and deliberately so: it blocks every lane, it had been red for hours with nobody on it, and its remedy needs no ruling. ⛔ If another seat owns this, say so and this card is theirs.Dedupe words:
OSV-Scanner devalue,GHSA-9rgm-9g3h-6x36,Validate Package Dependencies red on main,osv-scanner.toml exemption forbidden fixed version exists,pnpm-lock advisory.Generated by Claude Code