What happens
OSV-Scanner (validate-deps.yml, run 36510180397 on the Version Packages PR #17076) reports 7 Medium advisories in pnpm-lock.yaml:
Evidence that this is main's problem, not the release PR's
origin/main's pnpm-lock.yaml carries each of those locked versions: ip-address@10.4.0, ip-address@10.5.0, nodemailer@9.1.1, undici@7.29.0 and undici@8.9.0. The version PR changes only workspace versions. So every PR that touches a package.json, and the next scheduled scan of main, get the same red.
Fix
Take the fixed versions on main, following the convention of ca31ff66:
- declared floors and/or
pnpm overrides;
- the lockfile regenerated by
pnpm install, never edited by hand;
- no
osv-scanner.toml exemption.
nodemailer 9 → 10 is a major bump, so its call sites need to be checked against the 10.x breaking changes. A fix PR against main is in progress and will link here.
Generated by Claude Code
What happens
OSV-Scanner (
validate-deps.yml, run 36510180397 on the Version Packages PR #17076) reports 7 Medium advisories inpnpm-lock.yaml:ip-addressnodemailerundiciEvidence that this is main's problem, not the release PR's
origin/main'spnpm-lock.yamlcarries each of those locked versions:ip-address@10.4.0,ip-address@10.5.0,nodemailer@9.1.1,undici@7.29.0andundici@8.9.0. The version PR changes only workspace versions. So every PR that touches apackage.json, and the next scheduled scan ofmain, get the same red.Fix
Take the fixed versions on
main, following the convention ofca31ff66:pnpmoverrides;pnpm install, never edited by hand;osv-scanner.tomlexemption.nodemailer9 → 10 is a major bump, so its call sites need to be checked against the 10.x breaking changes. A fix PR againstmainis in progress and will link here.Generated by Claude Code