Skip to content

security(deps): apps/site next 16.3.3 carries GHSA-vcvr-r3jv-pc5j (critical): re-lock onto 16.3.6 (supersedes #11235 and #11236) #11356

Description

@objectstack-fleet

Filing-gate class: ③ maintainer-directed task. It is also ①: a security defect with a named site.
Routing: the maintainer direct-dispatch channel. This PM session (session_018gA1pE6eJtwHhqx72G8U9X) routes the card as the maintainer named it; the ruling is quoted below.
Acting reader: the domain:devx lane seat, which dispatches one os-dev.
Dedup: I listed objectui's issues and PRs over REST (every open item plus the 500 most recently updated closed ones, 585 in all) and grepped them for GHSA-vcvr, next@16.3.3, next 16.3.3, next/og and 16.3.6. There were 2 hits, both the Dependabot PRs this card supersedes (#11235 and #11236). Those hits also show the scan was live. No card exists for this.

Maintainer ruling (verbatim)

objectui 的 next 漏洞:我推荐立 p1 卡并关掉 #11235/#11236 同意

Given in session session_018gA1pE6eJtwHhqx72G8U9X on 2026-10-01, in reply to the seat's risk read of objectui's open Dependabot PRs.

The defect

Why the Dependabot PRs cannot carry the fix

Both are closed in favour of this card.

What to do

  1. In apps/site/package.json, move next from 16.3.3 to 16.3.6. Keep it an exact pin, as it is today.
  2. Regenerate pnpm-lock.yaml with the repo's tooling: pnpm install --lockfile-only, under the pnpm version that packageManager names (10.31.0). Start from origin/main's lockfile. Never edit it by hand.
  3. Acceptance:
    • The lockfile resolves next@16.3.6, and no next@16.3.3 remains.
    • node scripts/check-lockfile-integrity.mjs --base-ref origin/main reports no new physical copy and no backward move. This is the gate chore(deps): bump next from 16.3.3 to 16.3.6 #11236 failed.
    • pnpm install --frozen-lockfile passes.
    • Only next and its own @next/* dependencies move, plus snapshot keys that embed the next version.
    • The apps/site build passes on 16.3.6. It is the app that serves the vulnerable route.
  4. Changeset. apps/site is "private": true, and this changes no published package. Settle it with node scripts/check-changeset-presence.mjs, per objectui's AGENTS.md.

Generated by Claude Code

Activity

  1. added
    bugSomething isn't working
    domain:devxobjectui devx stream: fix lands on .github/, scripts/ or release pipeline — devx lane cross-repo
    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iterate
    and removed on Oct 1, 2026
  2. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 1
    Session: session_018gA1pE6eJtwHhqx72G8U9X
    Account: os-bill (the seat's linked user as GET /user answers it; the card's assignee from this act)
    Branch: claude/issue-11356-next-ghsa-relock
    Worktree: objectui-issue-11356
    Domain: domain:devx
    Seat: domain:devx#3 (the maintainer's direct-dispatch session; it holds no seat post, so #3 collides with no post: objectui devx seats 1 and 2 are #5748 and #10917)
    Provenance:

    • Who: the maintainer.
    • Verbatim: 「相关卡片你使用项目经理技能派发处理」, after 「objectui 的 next 漏洞:我推荐立 p1 卡并关掉 Bump next from 16.3.3 to 16.3.6 in /apps/site in the npm_and_yarn group across 1 directory #11235/chore(deps): bump next from 16.3.3 to 16.3.6 #11236 同意」.
    • Where: session session_018gA1pE6eJtwHhqx72G8U9X, 2026-10-01.
      File surface:
    • apps/site/package.json: only the next pin, 16.3.3 to 16.3.6, kept exact.
    • pnpm-lock.yaml: regenerated with pnpm install --lockfile-only under the packageManager pnpm (10.31.0), starting from origin/main's lockfile. ⛔ No hand edit.
    • A .changeset file only if scripts/check-changeset-presence.mjs asks for one. apps/site is "private": true.
    • Stop on a breach and explain it in the report.
      Container & model: S (one pin plus a tool-regenerated lockfile, judged by the lockfile-integrity gate), mode:subagent, model: opus. dispatch-gates --tier --repo objectstack-ai/objectui at objectstack 99398542b3: no path-derived mandate. The tier is above the S floor because the card is p1 security and the integrity gate can demand a judgment call.
      Clause-②: no
      Thread-read: none
      Serial constraints cleared:
    • Read at 2026-10-01T08:08Z over objectui's 8 open PRs.
    • Only feat(plugin-tree,plugin-map,types): object-tree and object-map are judged and publish the keys their renderers honour (objectui#11168 slice 3) #11335, a draft from another seat, touches pnpm-lock.yaml. None touches apps/site/**.
    • pnpm-lock.yaml is ordinary concurrency, not a single-writer path: the dev merges main right before opening the PR, and whichever lands second regenerates the lockfile.
    • No other open claim on this card.

    Generated by Claude Code

  3. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 11356,
      "status": "done",
      "branch": "claude/issue-11356-next-ghsa-relock",
      "pr": "https://github.com/objectstack-ai/objectui/pull/11361",
      "session": "session_018gA1pE6eJtwHhqx72G8U9X",
      "premise_still_valid": true,
      "summary": "apps/site/package.json moves the exact next pin from 16.3.3 to 16.3.6 (the next line only), and pnpm-lock.yaml was regenerated with `pnpm install --lockfile-only` under pnpm 10.31.0, starting from main's lockfile at 2124d04111 unchanged. The lockfile moves only next, @next/env and the eight @next/swc-* packages (packages: 10 out, 10 in, 1767 to 1767), plus the four snapshot keys that embed the next version as a peer: fumadocs-core, fumadocs-mdx, fumadocs-ui, and better-auth (optional next peer, via the packages/auth importer). Snapshots go 14 out, 14 in, 1773 to 1773; no new physical copy, and the string 16.3.3 is gone. All four hypotheses held: H1 no nanoid/vite copy, H2 one manifest declares next, H3 the site builds and typechecks on Next.js 16.3.6 and prerenders 184 og PNGs through ImageResponse, H4 no changeset owed. Draft PR #11361 is open (head 76e9ee3, assignee os-bill). main had not moved from 2124d04111 at PR time, so no merge was needed.",
      "tests": "All on head 76e9ee3 (`git rev-parse --short HEAD` = 76e9ee3), Node 22.23.3, pnpm 10.31.0. (1) `node scripts/check-lockfile-integrity.mjs --base-ref origin/main` exit 0: 'VERDICT clean — no @objectstack/* identity moved backward and no package gained a copy.' (1773 vs 1773 resolutions); `--json` gives findings/backward/duplicated all []; `--self-test` exit 0 (29 cases). (2) `pnpm install --frozen-lockfile` exit 0, and the installed apps/site/node_modules/next version is 16.3.6. Control leg: main's lockfile with this branch's manifest gives exit 1 ERR_PNPM_OUTDATED_LOCKFILE; restored with `git checkout HEAD -- pnpm-lock.yaml`, `git diff HEAD` empty, hash-object 0b17701487 == HEAD blob. (3) `node scripts/check-lockfile-dedupe.mjs` (bare) exit 0 'VERDICT deduped'; `--self-test` exit 0 (32 cases). (4) Under os-verify-lock: `pnpm turbo run build --filter='@object-ui/site^...' --concurrency=2` VERDICT command-exit 0, 29/29; then CI's exact `pnpm turbo run build --filter='@object-ui/site' --concurrency=2` VERDICT command-exit 0, 30/30 with 29 cached, so the site task really ran: 'Next.js 16.3.6 (Turbopack)', 'Generating static pages (559/559)', 184 .next/server/app/og/**/image.png.body files with a PNG magic header. (5) `pnpm --filter @object-ui/site type-check` (script name echoed: fumadocs-mdx && next typegen && tsc --noEmit) VERDICT command-exit 0. (6) `pnpm --filter @object-ui/auth type-check && pnpm exec vitest run --maxWorkers=2 packages/auth/` VERDICT command-exit 0: 'Test Files 28 passed (28) / Tests 282 passed (282)'. (7) The 10 test files that read pnpm-lock.yaml or resolve through apps/site (ci-cd-pipeline-doc, docs-build-trigger, check-installed-spec-pin-claims, check-lockfile-integrity, check-lockfile-dedupe, check-pre-install-import-graph, markdown-test-inputs, check-doc-links, check-changeset-presence, MetadataService.specKeyReference) VERDICT command-exit 0: 'Test Files 10 passed (10) / Tests 479 passed (479)'. (8) `node scripts/check-changeset-presence.mjs` exit 0: 'no changeset is owed'. (9) check:control-bytes, check:new-line-citations, check:pre-install-import-graph, check:phantom-deps, check:unused-deps, type-check:coverage all exit 0. `check-governed-queue-guard.mjs --test` reports NOT GOVERNED. The control-byte self-scan grep exits 1 (no match). (10) OSV-Scanner v2.3.8 (sha256 bc98e153 matches the release SUMS), offline: main has 62 rows and 1 Critical, the branch has 61 rows and 0 Critical. The row diff is exactly GHSA-vcvr-r3jv-pc5j next 16.3.3 removed, with nothing added. NOT MEASURED locally, declared to CI: repo-wide `pnpm lint` (CI-owned; the diff touches only .json/.yaml, outside every `files` glob of eslint.config.js, which is not type-aware; read from the config, not counted with --format json), repo-wide `pnpm type-check`, the 8 test shards, coverage, Build & E2E, Bundle Analysis. No ablation applies (no code change). CI snapshot at report time on 76e9ee3: 42 check runs. Lockfile Integrity Check, Lockfile Dedupe Check, Changeset Declaration and Governed Surface Queue Guard are success; Type Check, Lint, Build Docs and the Test shards are in_progress.",
      "mcp_calls": "0 — no MCP GitHub tool used (reads went through gh api single-resource GETs)",
      "api_writes": "3 — all via scripts/pm fleet-write relay (seat side POST /repos/objectstack-ai/objectstack/dispatches each): (1) pr_create, POST /repos/objectstack-ai/objectui/pulls, giving #11361 (read-back 6680 bytes identical); (2) label-write --assign os-bill, POST /repos/objectstack-ai/objectui/issues/11361/assignees (read-back MATCHES); (3) this os-dev-report comment, POST /repos/objectstack-ai/objectui/issues/11356/comments. There were also 2 git pushes (the empty-branch probe and 76e9ee3), which are not REST writes. Zero label writes (no labels named by the dispatch; dependencies and apps were put there by labeler.yml).",
      "open_questions": [],
      "out_of_scope_findings": [
        "class: b · Seam: root package.json engines.node '>=22.11' (restated in CONTRIBUTING.md 'Node.js 22.11 or higher' and QUICK_REFERENCE.md) to install-time enforcement via .npmrc engine-strict=true | consumer: pnpm install · reach: `pnpm install --frozen-lockfile` at 2124d04111 on Node v22.22.0 (which the declared floor admits) gives exit 1 ERR_PNPM_UNSUPPORTED_ENGINE 'Your Node version is incompatible with jsdom@30.0.1(@noble/hashes@2.3.0). Expected version: ^22.22.2 || ^24.15.0 || >=26.0.0' (measured in this container). The .npmrc comment tells the reader to 'upgrade node/pnpm to the declared floors', which does not fix it. Either the floor or the jsdom resolution is the defect; the producer is the root engines field. · dedupe words: engines.node, ERR_PNPM_UNSUPPORTED_ENGINE, jsdom engines, 22.22.2, engine-strict",
        "carrier: Dependabot alerts on objectui's default branch plus the PM seat's Dependabot risk read · OSV offline over main's pnpm-lock.yaml still reads 61 rows (18 High, e.g. undici 7.29.0/8.9.0, hono 4.13.2, joi 18.2.3, ip-address 10.5.0), all pre-existing and untouched by this PR · noted, not filed",
        "carrier: PM seat · the push banner said '2 critical' Dependabot alerts on the default branch, but OSV over pnpm-lock.yaml reads only 1 Critical (the next row fixed here). NOT MEASURED where the second comes from (another manifest, or a severity difference) · noted, not filed"
      ],
      "gates": [
        {
          "gate": "lockfile-integrity",
          "command": "node scripts/check-lockfile-integrity.mjs --base-ref origin/main",
          "exit": 0,
          "verdict": "VERDICT clean"
        },
        {
          "gate": "lockfile-integrity self-test",
          "command": "node scripts/check-lockfile-integrity.mjs --self-test",
          "exit": 0,
          "verdict": "29 cases pass"
        },
        {
          "gate": "frozen install",
          "command": "pnpm install --frozen-lockfile",
          "exit": 0,
          "verdict": "installed next 16.3.6"
        },
        {
          "gate": "frozen install control (main lockfile + new pin)",
          "command": "pnpm install --frozen-lockfile",
          "exit": 1,
          "verdict": "ERR_PNPM_OUTDATED_LOCKFILE (expected); restored, diff HEAD empty"
        },
        {
          "gate": "lockfile-dedupe",
          "command": "node scripts/check-lockfile-dedupe.mjs",
          "exit": 0,
          "verdict": "VERDICT deduped"
        },
        {
          "gate": "site closure build",
          "command": "os-verify-lock: pnpm turbo run build --filter='@object-ui/site^...' --concurrency=2",
          "exit": 0,
          "verdict": "VERDICT command-exit 0, 29/29"
        },
        {
          "gate": "Build Docs (site build)",
          "command": "os-verify-lock: pnpm turbo run build --filter='@object-ui/site' --concurrency=2",
          "exit": 0,
          "verdict": "VERDICT command-exit 0, 30/30, Next.js 16.3.6, 184 og PNGs"
        },
        {
          "gate": "site type-check",
          "command": "os-verify-lock: pnpm --filter @object-ui/site type-check",
          "exit": 0,
          "verdict": "VERDICT command-exit 0"
        },
        {
          "gate": "auth type-check + tests",
          "command": "os-verify-lock: pnpm --filter @object-ui/auth type-check && pnpm exec vitest run --maxWorkers=2 packages/auth/",
          "exit": 0,
          "verdict": "28 files / 282 tests passed"
        },
        {
          "gate": "lockfile-reading tests",
          "command": "os-verify-lock: pnpm exec vitest run --maxWorkers=2 (10 named files)",
          "exit": 0,
          "verdict": "10 files / 479 tests passed"
        },
        {
          "gate": "changeset presence",
          "command": "node scripts/check-changeset-presence.mjs",
          "exit": 0,
          "verdict": "no changeset is owed"
        },
        {
          "gate": "control bytes",
          "command": "pnpm check:control-bytes",
          "exit": 0,
          "verdict": "OK"
        },
        {
          "gate": "line citations",
          "command": "pnpm check:new-line-citations",
          "exit": 0,
          "verdict": "0 new citation(s)"
        },
        {
          "gate": "pre-install import graph",
          "command": "pnpm check:pre-install-import-graph",
          "exit": 0,
          "verdict": "OK"
        },
        {
          "gate": "phantom deps",
          "command": "pnpm check:phantom-deps",
          "exit": 0,
          "verdict": "OK"
        },
        {
          "gate": "unused deps",
          "command": "pnpm check:unused-deps",
          "exit": 0,
          "verdict": "OK"
        },
        {
          "gate": "type-check coverage",
          "command": "pnpm type-check:coverage",
          "exit": 0,
          "verdict": "43/43"
        },
        {
          "gate": "governed surface",
          "command": "node scripts/check-governed-queue-guard.mjs --test apps/site/package.json pnpm-lock.yaml",
          "exit": 0,
          "verdict": "NOT GOVERNED"
        },
        {
          "gate": "OSV before (main 2124d04111)",
          "command": "osv-scanner v2.3.8 scan --offline-vulnerabilities --lockfile",
          "exit": 1,
          "verdict": "62 rows, 1 Critical (next GHSA-vcvr-r3jv-pc5j)"
        },
        {
          "gate": "OSV after (76e9ee3)",
          "command": "osv-scanner v2.3.8 scan --offline-vulnerabilities --lockfile",
          "exit": 1,
          "verdict": "61 rows, 0 Critical; only diff = the next row removed"
        },
        {
          "gate": "repo-wide lint / type-check / test shards / coverage / Build & E2E / Bundle Analysis",
          "command": "CI",
          "exit": null,
          "verdict": "NOT MEASURED locally, declared to CI; in_progress at report time"
        }
      ],
      "line_budget": "n/a — no skills/** or governed ledger touched",
      "deviations": [
        "Node 22.23.3 (checksum-verified tarball in the scratch dir, put on PATH per command) instead of the container's 22.22.0, which engine-strict refuses for jsdom@30.0.1; engine-strict was not disabled and nothing in the repo changed for it (see finding 1)",
        "dispatch-gates.mjs not used (it refuses outside objectstack); gate set derived by hand from objectui's ci.yml (Build Docs path list includes pnpm-lock.yaml), lint.yml, lockfile-integrity.yml, lockfile-dedupe.yml, performance-budget.yml, changeset-presence.yml",
        "site build run as two lock calls (dependency closure, then CI's exact command), to stay under the 10-minute foreground cap; the second call is the Build Docs command verbatim",
        "commit trailers use objectui AGENTS.md's model-free pair (Claude-Session + Co-authored-by: Claude) instead of the harness reminder's model-named Co-Authored-By; the PR footer uses the session-URL form from the os-dev contract instead of the harness reminder's form"
      ],
      "files_changed": [
        "apps/site/package.json (+1/-1, the next line only)",
        "pnpm-lock.yaml (+55/-55, regenerated by pnpm install --lockfile-only)"
      ]
    }

    Generated by Claude Code

  4. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Review: ACCEPT, PR #11361 (head 76e9ee3657)

    Reviewed 2026-10-01T08:33Z by the PM seat (session_018gA1pE6eJtwHhqx72G8U9X) against GitHub, not against the report.

    Checklist

    • Shape: the PR is a draft against main. Its body's first line is Fixes #11356, and it has no other closing keyword. The assignee is os-bill, mirroring the card.
    • Scope: 2 files. apps/site/package.json changes only "next": "16.3.3" to "16.3.6". pnpm-lock.yaml (+55/−55) moves only next, @next/env and the eight @next/swc-* packages, plus snapshot keys that embed the next version (better-auth, fumadocs-core, fumadocs-mdx, fumadocs-ui, none of which changes version). 16.3.3 appears 0 times on the head.
    • Changeset: none is owed. apps/site is "private": true, and the report records check-changeset-presence.mjs's "no changeset is owed".
    • Governed surface: neither path is on it.

    Spot-checked readings: the dev's local lockfile-integrity "VERDICT clean", the frozen install with its negative control, and the OSV before/after (1 Critical down to 0; the only removed row is GHSA-vcvr-r3jv-pc5j). CI on this head at review time: 28 success, 11 still running, 0 failed. Lint, Type Check and the test shards are not yet concluded, and the seat lands only once every check is green.

    Deviations, accepted:

    • The build ran on Node 22.23.3 instead of the container's 22.22.0, because engine-strict refuses 22.22.0 for jsdom. That refusal is a defect of its own, filed below.
    • The gate set was hand-derived, because dispatch-gates.mjs refuses outside objectstack.

    Out-of-scope findings


    Generated by Claude Code

  5. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: #11361 merged, GHSA-vcvr-r3jv-pc5j fixed on main


    Generated by Claude Code

  6. added a commit that references this issue on Oct 7, 2026
    ad58cc1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxobjectui devx stream: fix lands on .github/, scripts/ or release pipeline — devx lane cross-repopriority:p1security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions