Repository navigation
security(deps): apps/site next 16.3.3 carries GHSA-vcvr-r3jv-pc5j (critical): re-lock onto 16.3.6 (supersedes #11235 and #11236) #11356
Description
Activity
- addedbugSomething isn't workingSomething isn't workingdomain:devxobjectui devx stream: fix lands on .github/, scripts/ or release pipeline — devx lane cross-repoobjectui devx stream: fix lands on .github/, scripts/ or release pipeline — devx lane cross-repoarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iterateand removed
on Oct 1, 2026 objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsClaim: PM loop round 1
Session:session_018gA1pE6eJtwHhqx72G8U9X
Account:os-bill(the seat's linked user asGET /useranswers it; the card's assignee from this act)
Branch:claude/issue-11356-next-ghsa-relock
Worktree:objectui-issue-11356
Domain:domain:devx
Seat: domain:devx#3 (the maintainer's direct-dispatch session; it holds no seat post, so #3 collides with no post: objectui devx seats 1 and 2 are #5748 and #10917)
Provenance:- Who: the maintainer.
- Verbatim: 「相关卡片你使用项目经理技能派发处理」, after 「objectui 的 next 漏洞:我推荐立 p1 卡并关掉 Bump next from 16.3.3 to 16.3.6 in /apps/site in the npm_and_yarn group across 1 directory #11235/chore(deps): bump next from 16.3.3 to 16.3.6 #11236 同意」.
- Where: session
session_018gA1pE6eJtwHhqx72G8U9X, 2026-10-01.
File surface: apps/site/package.json: only thenextpin,16.3.3to16.3.6, kept exact.pnpm-lock.yaml: regenerated withpnpm install --lockfile-onlyunder thepackageManagerpnpm (10.31.0), starting fromorigin/main's lockfile. ⛔ No hand edit.- A
.changesetfile only ifscripts/check-changeset-presence.mjsasks for one.apps/siteis"private": true. - Stop on a breach and explain it in the report.
Container & model:S(one pin plus a tool-regenerated lockfile, judged by the lockfile-integrity gate),mode:subagent,model: opus.dispatch-gates --tier --repo objectstack-ai/objectuiat objectstack99398542b3: no path-derived mandate. The tier is above the S floor because the card is p1 security and the integrity gate can demand a judgment call.
Clause-②: no
Thread-read: none
Serial constraints cleared: - Read at 2026-10-01T08:08Z over objectui's 8 open PRs.
- Only feat(plugin-tree,plugin-map,types): object-tree and object-map are judged and publish the keys their renderers honour (objectui#11168 slice 3) #11335, a draft from another seat, touches
pnpm-lock.yaml. None touchesapps/site/**. pnpm-lock.yamlis ordinary concurrency, not a single-writer path: the dev mergesmainright before opening the PR, and whichever lands second regenerates the lockfile.- No other open claim on this card.
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 11356, "status": "done", "branch": "claude/issue-11356-next-ghsa-relock", "pr": "https://github.com/objectstack-ai/objectui/pull/11361", "session": "session_018gA1pE6eJtwHhqx72G8U9X", "premise_still_valid": true, "summary": "apps/site/package.json moves the exact next pin from 16.3.3 to 16.3.6 (the next line only), and pnpm-lock.yaml was regenerated with `pnpm install --lockfile-only` under pnpm 10.31.0, starting from main's lockfile at 2124d04111 unchanged. The lockfile moves only next, @next/env and the eight @next/swc-* packages (packages: 10 out, 10 in, 1767 to 1767), plus the four snapshot keys that embed the next version as a peer: fumadocs-core, fumadocs-mdx, fumadocs-ui, and better-auth (optional next peer, via the packages/auth importer). Snapshots go 14 out, 14 in, 1773 to 1773; no new physical copy, and the string 16.3.3 is gone. All four hypotheses held: H1 no nanoid/vite copy, H2 one manifest declares next, H3 the site builds and typechecks on Next.js 16.3.6 and prerenders 184 og PNGs through ImageResponse, H4 no changeset owed. Draft PR #11361 is open (head 76e9ee3, assignee os-bill). main had not moved from 2124d04111 at PR time, so no merge was needed.", "tests": "All on head 76e9ee3 (`git rev-parse --short HEAD` = 76e9ee3), Node 22.23.3, pnpm 10.31.0. (1) `node scripts/check-lockfile-integrity.mjs --base-ref origin/main` exit 0: 'VERDICT clean — no @objectstack/* identity moved backward and no package gained a copy.' (1773 vs 1773 resolutions); `--json` gives findings/backward/duplicated all []; `--self-test` exit 0 (29 cases). (2) `pnpm install --frozen-lockfile` exit 0, and the installed apps/site/node_modules/next version is 16.3.6. Control leg: main's lockfile with this branch's manifest gives exit 1 ERR_PNPM_OUTDATED_LOCKFILE; restored with `git checkout HEAD -- pnpm-lock.yaml`, `git diff HEAD` empty, hash-object 0b17701487 == HEAD blob. (3) `node scripts/check-lockfile-dedupe.mjs` (bare) exit 0 'VERDICT deduped'; `--self-test` exit 0 (32 cases). (4) Under os-verify-lock: `pnpm turbo run build --filter='@object-ui/site^...' --concurrency=2` VERDICT command-exit 0, 29/29; then CI's exact `pnpm turbo run build --filter='@object-ui/site' --concurrency=2` VERDICT command-exit 0, 30/30 with 29 cached, so the site task really ran: 'Next.js 16.3.6 (Turbopack)', 'Generating static pages (559/559)', 184 .next/server/app/og/**/image.png.body files with a PNG magic header. (5) `pnpm --filter @object-ui/site type-check` (script name echoed: fumadocs-mdx && next typegen && tsc --noEmit) VERDICT command-exit 0. (6) `pnpm --filter @object-ui/auth type-check && pnpm exec vitest run --maxWorkers=2 packages/auth/` VERDICT command-exit 0: 'Test Files 28 passed (28) / Tests 282 passed (282)'. (7) The 10 test files that read pnpm-lock.yaml or resolve through apps/site (ci-cd-pipeline-doc, docs-build-trigger, check-installed-spec-pin-claims, check-lockfile-integrity, check-lockfile-dedupe, check-pre-install-import-graph, markdown-test-inputs, check-doc-links, check-changeset-presence, MetadataService.specKeyReference) VERDICT command-exit 0: 'Test Files 10 passed (10) / Tests 479 passed (479)'. (8) `node scripts/check-changeset-presence.mjs` exit 0: 'no changeset is owed'. (9) check:control-bytes, check:new-line-citations, check:pre-install-import-graph, check:phantom-deps, check:unused-deps, type-check:coverage all exit 0. `check-governed-queue-guard.mjs --test` reports NOT GOVERNED. The control-byte self-scan grep exits 1 (no match). (10) OSV-Scanner v2.3.8 (sha256 bc98e153 matches the release SUMS), offline: main has 62 rows and 1 Critical, the branch has 61 rows and 0 Critical. The row diff is exactly GHSA-vcvr-r3jv-pc5j next 16.3.3 removed, with nothing added. NOT MEASURED locally, declared to CI: repo-wide `pnpm lint` (CI-owned; the diff touches only .json/.yaml, outside every `files` glob of eslint.config.js, which is not type-aware; read from the config, not counted with --format json), repo-wide `pnpm type-check`, the 8 test shards, coverage, Build & E2E, Bundle Analysis. No ablation applies (no code change). CI snapshot at report time on 76e9ee3: 42 check runs. Lockfile Integrity Check, Lockfile Dedupe Check, Changeset Declaration and Governed Surface Queue Guard are success; Type Check, Lint, Build Docs and the Test shards are in_progress.", "mcp_calls": "0 — no MCP GitHub tool used (reads went through gh api single-resource GETs)", "api_writes": "3 — all via scripts/pm fleet-write relay (seat side POST /repos/objectstack-ai/objectstack/dispatches each): (1) pr_create, POST /repos/objectstack-ai/objectui/pulls, giving #11361 (read-back 6680 bytes identical); (2) label-write --assign os-bill, POST /repos/objectstack-ai/objectui/issues/11361/assignees (read-back MATCHES); (3) this os-dev-report comment, POST /repos/objectstack-ai/objectui/issues/11356/comments. There were also 2 git pushes (the empty-branch probe and 76e9ee3), which are not REST writes. Zero label writes (no labels named by the dispatch; dependencies and apps were put there by labeler.yml).", "open_questions": [], "out_of_scope_findings": [ "class: b · Seam: root package.json engines.node '>=22.11' (restated in CONTRIBUTING.md 'Node.js 22.11 or higher' and QUICK_REFERENCE.md) to install-time enforcement via .npmrc engine-strict=true | consumer: pnpm install · reach: `pnpm install --frozen-lockfile` at 2124d04111 on Node v22.22.0 (which the declared floor admits) gives exit 1 ERR_PNPM_UNSUPPORTED_ENGINE 'Your Node version is incompatible with jsdom@30.0.1(@noble/hashes@2.3.0). Expected version: ^22.22.2 || ^24.15.0 || >=26.0.0' (measured in this container). The .npmrc comment tells the reader to 'upgrade node/pnpm to the declared floors', which does not fix it. Either the floor or the jsdom resolution is the defect; the producer is the root engines field. · dedupe words: engines.node, ERR_PNPM_UNSUPPORTED_ENGINE, jsdom engines, 22.22.2, engine-strict", "carrier: Dependabot alerts on objectui's default branch plus the PM seat's Dependabot risk read · OSV offline over main's pnpm-lock.yaml still reads 61 rows (18 High, e.g. undici 7.29.0/8.9.0, hono 4.13.2, joi 18.2.3, ip-address 10.5.0), all pre-existing and untouched by this PR · noted, not filed", "carrier: PM seat · the push banner said '2 critical' Dependabot alerts on the default branch, but OSV over pnpm-lock.yaml reads only 1 Critical (the next row fixed here). NOT MEASURED where the second comes from (another manifest, or a severity difference) · noted, not filed" ], "gates": [ { "gate": "lockfile-integrity", "command": "node scripts/check-lockfile-integrity.mjs --base-ref origin/main", "exit": 0, "verdict": "VERDICT clean" }, { "gate": "lockfile-integrity self-test", "command": "node scripts/check-lockfile-integrity.mjs --self-test", "exit": 0, "verdict": "29 cases pass" }, { "gate": "frozen install", "command": "pnpm install --frozen-lockfile", "exit": 0, "verdict": "installed next 16.3.6" }, { "gate": "frozen install control (main lockfile + new pin)", "command": "pnpm install --frozen-lockfile", "exit": 1, "verdict": "ERR_PNPM_OUTDATED_LOCKFILE (expected); restored, diff HEAD empty" }, { "gate": "lockfile-dedupe", "command": "node scripts/check-lockfile-dedupe.mjs", "exit": 0, "verdict": "VERDICT deduped" }, { "gate": "site closure build", "command": "os-verify-lock: pnpm turbo run build --filter='@object-ui/site^...' --concurrency=2", "exit": 0, "verdict": "VERDICT command-exit 0, 29/29" }, { "gate": "Build Docs (site build)", "command": "os-verify-lock: pnpm turbo run build --filter='@object-ui/site' --concurrency=2", "exit": 0, "verdict": "VERDICT command-exit 0, 30/30, Next.js 16.3.6, 184 og PNGs" }, { "gate": "site type-check", "command": "os-verify-lock: pnpm --filter @object-ui/site type-check", "exit": 0, "verdict": "VERDICT command-exit 0" }, { "gate": "auth type-check + tests", "command": "os-verify-lock: pnpm --filter @object-ui/auth type-check && pnpm exec vitest run --maxWorkers=2 packages/auth/", "exit": 0, "verdict": "28 files / 282 tests passed" }, { "gate": "lockfile-reading tests", "command": "os-verify-lock: pnpm exec vitest run --maxWorkers=2 (10 named files)", "exit": 0, "verdict": "10 files / 479 tests passed" }, { "gate": "changeset presence", "command": "node scripts/check-changeset-presence.mjs", "exit": 0, "verdict": "no changeset is owed" }, { "gate": "control bytes", "command": "pnpm check:control-bytes", "exit": 0, "verdict": "OK" }, { "gate": "line citations", "command": "pnpm check:new-line-citations", "exit": 0, "verdict": "0 new citation(s)" }, { "gate": "pre-install import graph", "command": "pnpm check:pre-install-import-graph", "exit": 0, "verdict": "OK" }, { "gate": "phantom deps", "command": "pnpm check:phantom-deps", "exit": 0, "verdict": "OK" }, { "gate": "unused deps", "command": "pnpm check:unused-deps", "exit": 0, "verdict": "OK" }, { "gate": "type-check coverage", "command": "pnpm type-check:coverage", "exit": 0, "verdict": "43/43" }, { "gate": "governed surface", "command": "node scripts/check-governed-queue-guard.mjs --test apps/site/package.json pnpm-lock.yaml", "exit": 0, "verdict": "NOT GOVERNED" }, { "gate": "OSV before (main 2124d04111)", "command": "osv-scanner v2.3.8 scan --offline-vulnerabilities --lockfile", "exit": 1, "verdict": "62 rows, 1 Critical (next GHSA-vcvr-r3jv-pc5j)" }, { "gate": "OSV after (76e9ee3)", "command": "osv-scanner v2.3.8 scan --offline-vulnerabilities --lockfile", "exit": 1, "verdict": "61 rows, 0 Critical; only diff = the next row removed" }, { "gate": "repo-wide lint / type-check / test shards / coverage / Build & E2E / Bundle Analysis", "command": "CI", "exit": null, "verdict": "NOT MEASURED locally, declared to CI; in_progress at report time" } ], "line_budget": "n/a — no skills/** or governed ledger touched", "deviations": [ "Node 22.23.3 (checksum-verified tarball in the scratch dir, put on PATH per command) instead of the container's 22.22.0, which engine-strict refuses for jsdom@30.0.1; engine-strict was not disabled and nothing in the repo changed for it (see finding 1)", "dispatch-gates.mjs not used (it refuses outside objectstack); gate set derived by hand from objectui's ci.yml (Build Docs path list includes pnpm-lock.yaml), lint.yml, lockfile-integrity.yml, lockfile-dedupe.yml, performance-budget.yml, changeset-presence.yml", "site build run as two lock calls (dependency closure, then CI's exact command), to stay under the 10-minute foreground cap; the second call is the Build Docs command verbatim", "commit trailers use objectui AGENTS.md's model-free pair (Claude-Session + Co-authored-by: Claude) instead of the harness reminder's model-named Co-Authored-By; the PR footer uses the session-URL form from the os-dev contract instead of the harness reminder's form" ], "files_changed": [ "apps/site/package.json (+1/-1, the next line only)", "pnpm-lock.yaml (+55/-55, regenerated by pnpm install --lockfile-only)" ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsReview: ACCEPT, PR #11361 (head
76e9ee3657)Reviewed 2026-10-01T08:33Z by the PM seat (
session_018gA1pE6eJtwHhqx72G8U9X) against GitHub, not against the report.Checklist
- Shape: the PR is a draft against
main. Its body's first line isFixes #11356, and it has no other closing keyword. The assignee isos-bill, mirroring the card. - Scope: 2 files.
apps/site/package.jsonchanges only"next": "16.3.3"to"16.3.6".pnpm-lock.yaml(+55/−55) moves onlynext,@next/envand the eight@next/swc-*packages, plus snapshot keys that embed the next version (better-auth,fumadocs-core,fumadocs-mdx,fumadocs-ui, none of which changes version).16.3.3appears 0 times on the head. - Changeset: none is owed.
apps/siteis"private": true, and the report recordscheck-changeset-presence.mjs's "no changeset is owed". - Governed surface: neither path is on it.
Spot-checked readings: the dev's local lockfile-integrity "VERDICT clean", the frozen install with its negative control, and the OSV before/after (1 Critical down to 0; the only removed row is GHSA-vcvr-r3jv-pc5j). CI on this head at review time: 28 success, 11 still running, 0 failed. Lint, Type Check and the test shards are not yet concluded, and the seat lands only once every check is green.
Deviations, accepted:
- The build ran on Node 22.23.3 instead of the container's 22.22.0, because engine-strict refuses 22.22.0 for jsdom. That refusal is a defect of its own, filed below.
- The gate set was hand-derived, because
dispatch-gates.mjsrefuses outside objectstack.
Out-of-scope findings
- The engines floor contradicts
jsdom@30.0.1under engine-strict: filed [finding] root engines.node ">=22.11" admits Node versions thatpnpm installrefuses under engine-strict (jsdom@30.0.1 needs ^22.22.2) #11366, re-measured by the seat. - Pre-existing OSV High rows in
main's lockfile (undici, hono, joi, ip-address and others): noted, not filed. The carrier is the repository's Dependabot alerts, and this PR touches none of them. - The push banner said "2 critical" while OSV reads 1: noted, not filed. NOT MEASURED where the second alert comes from.
Generated by Claude Code
- Shape: the PR is a draft against
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsLanded: #11361 merged, GHSA-vcvr-r3jv-pc5j fixed on
main- The merge: fix(site): move next 16.3.3 to 16.3.6 for GHSA-vcvr-r3jv-pc5j (critical) #11361 merged at 2026-10-01T09:00:20Z through the merge queue, as
ad58cc1594(a squash: one parent). That commit is an ancestor of objectuiorigin/main. - The fix is on
main:apps/site/package.jsonpins"next": "16.3.6", andpnpm-lock.yamlholds 0 occurrences ofnext@16.3.3. - The card's state label:
Fixes #11356closed this cardcompleted, but thepm:dispatchedlabel survived the close. It is removed in this same write. - The follow-up finding from this card's report is filed as [finding] root engines.node ">=22.11" admits Node versions that
pnpm installrefuses under engine-strict (jsdom@30.0.1 needs ^22.22.2) #11366: the rootenginesfloor contradictsjsdom@30.0.1under engine-strict.
Generated by Claude Code
- The merge: fix(site): move next 16.3.3 to 16.3.6 for GHSA-vcvr-r3jv-pc5j (critical) #11361 merged at 2026-10-01T09:00:20Z through the merge queue, as
- added a commit that references this issue
on Oct 7, 2026
Filing-gate class: ③ maintainer-directed task. It is also ①: a security defect with a named site.
Routing: the maintainer direct-dispatch channel. This PM session (
session_018gA1pE6eJtwHhqx72G8U9X) routes the card as the maintainer named it; the ruling is quoted below.Acting reader: the
domain:devxlane seat, which dispatches oneos-dev.Dedup: I listed objectui's issues and PRs over REST (every open item plus the 500 most recently updated closed ones, 585 in all) and grepped them for
GHSA-vcvr,next@16.3.3,next 16.3.3,next/ogand16.3.6. There were 2 hits, both the Dependabot PRs this card supersedes (#11235 and #11236). Those hits also show the scan was live. No card exists for this.Maintainer ruling (verbatim)
Given in session
session_018gA1pE6eJtwHhqx72G8U9Xon 2026-10-01, in reply to the seat's risk read of objectui's open Dependabot PRs.The defect
next16.3.3 carries GHSA-vcvr-r3jv-pc5j: critical, CVSS 9.5, "Remote Code Execution in next/og ImageResponse". It is fixed in 16.3.6.mainis affected (read at2124d04111).apps/site/package.jsonpins"next": "16.3.3", andpnpm-lock.yamlresolvesnext@16.3.3.apps/site/app/og/docs/[...slug]/route.tsximports{ ImageResponse } from 'next/og', which is exactly the surface the advisory names. No other objectui manifest declaresnext.next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.jsonobjectstack#21055.Why the Dependabot PRs cannot carry the fix
Both are closed in favour of this card.
Lockfile Integrity Checkreports "nanoid gained a physical copy: 2 -> 3" (3.3.19 added) and "vite gained a physical copy: 2 -> 3" (vite 8.3.1 added). A test shard fails on the same finding. The PR was also 48 commits behindmain.ERR_PNPM_OUTDATED_LOCKFILE.What to do
apps/site/package.json, movenextfrom16.3.3to16.3.6. Keep it an exact pin, as it is today.pnpm-lock.yamlwith the repo's tooling:pnpm install --lockfile-only, under the pnpm version thatpackageManagernames (10.31.0). Start fromorigin/main's lockfile. Never edit it by hand.next@16.3.6, and nonext@16.3.3remains.node scripts/check-lockfile-integrity.mjs --base-ref origin/mainreports no new physical copy and no backward move. This is the gate chore(deps): bump next from 16.3.3 to 16.3.6 #11236 failed.pnpm install --frozen-lockfilepasses.nextand its own@next/*dependencies move, plus snapshot keys that embed thenextversion.apps/sitebuild passes on 16.3.6. It is the app that serves the vulnerable route.apps/siteis"private": true, and this changes no published package. Settle it withnode scripts/check-changeset-presence.mjs, per objectui's AGENTS.md.Generated by Claude Code