Skip to content

[finding] main's lockfile carries 7 OSV advisories (ip-address, nodemailer, undici) — Validate Package Dependencies is red on the 17.5.0 Version Packages PR #20561

Description

@hotlong

What happens

OSV-Scanner (validate-deps.yml, run 36510180397 on the Version Packages PR #17076) reports 7 Medium advisories in pnpm-lock.yaml:

package locked fixed in advisories
ip-address 10.4.0, 10.5.0 10.5.1 GHSA-2vr4-cq9g-pvrc, GHSA-rpw4-54j3-4h4q
nodemailer 9.1.1 10.0.2 (major) GHSA-6vj9-mwq6-2f5v
undici 7.29.0 / 8.9.0 7.29.1 / 8.10.2 GHSA-3wwx-pv8p-q78v

Evidence that this is main's problem, not the release PR's

origin/main's pnpm-lock.yaml carries each of those locked versions: ip-address@10.4.0, ip-address@10.5.0, nodemailer@9.1.1, undici@7.29.0 and undici@8.9.0. The version PR changes only workspace versions. So every PR that touches a package.json, and the next scheduled scan of main, get the same red.

Fix

Take the fixed versions on main, following the convention of ca31ff66:

  • declared floors and/or pnpm overrides;
  • the lockfile regenerated by pnpm install, never edited by hand;
  • no osv-scanner.toml exemption.

nodemailer 9 → 10 is a major bump, so its call sites need to be checked against the 10.x breaking changes. A fix PR against main is in progress and will link here.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxpm:dispatchedpriority:p1High: required for production / M2securitytooling

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions