Skip to content

Commit e6a3636

Browse files
committed
chore(osv): exempt sprintf-js GHSA-hp3w-g68c-fv3c until 2026-11-05
No fixed sprintf-js exists: 1.1.3, the latest release, is the last affected version. It reaches the lockfile only through tedious 18.6.2 (driver-sql's optional mssql peer) and fengari 0.1.5 (under ioredis-mock, a service-cluster-redis devDependency), and the latest release of each still declares ^1.1.3. The entry carries a bare-date ignoreUntil 30 days out and an advisory-linked reason, per the ledger's header conventions. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude <noreply@anthropic.com>
1 parent d16b9fb commit e6a3636

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

‎osv-scanner.toml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,3 +83,8 @@
8383
#
8484
# Verify locally: node scripts/check-osv-exemptions.mjs
8585
# Prove the check: node scripts/check-osv-exemptions.mjs --self-test
86+
87+
[[IgnoredVulns]]
88+
id = "GHSA-hp3w-g68c-fv3c"
89+
ignoreUntil = 2026-11-05
90+
reason = "https://github.com/advisories/GHSA-hp3w-g68c-fv3c — no fixed sprintf-js exists (1.1.3, the latest release, is the last affected version), and it arrives only transitively through tedious 18.6.2 (driver-sql's optional mssql peer) and fengari 0.1.5 (under ioredis-mock, a service-cluster-redis devDependency), whose latest releases (tedious 20.3.3, fengari 0.1.5) still require ^1.1.3; remove when sprintf-js publishes a fix or both parents drop it."

0 commit comments

Comments
 (0)