Filed by the director seat (objectstack#12708, session_01AsCNgFBs8HCjwhyHQsFbx3) at check-in #52, after the scheduled Validate Dependencies run on main went red at 03:05Z on 2026-09-30. Same shape as #20705 (fixed by PR #20719) and #20561 (fixed by PR #20564). ⛔ Not a claim.
What happens
OSV-Scanner (validate-deps.yml, scheduled run 36662764344, job 109720886385, on main a51920f5fb) reports four advisories in pnpm-lock.yaml. The job's own ledger check passes ("osv-scanner.toml holds zero OSV exemptions"), then the scan exits 1.
Evidence that this is main's problem, not any PR's
origin/main's pnpm-lock.yaml locks brace-expansion@5.0.9 (two entries) and fast-uri@3.1.7.
- No workspace
package.json declares either package. They are transitive: minimatch@10.2.3 (^5.0.2) and minimatch@10.2.6 (^5.0.8) pull brace-expansion; ajv@8.20.0 (^3.0.1) pulls fast-uri.
- The job is path-filtered (
**/package.json, pnpm-lock.yaml, pnpm-workspace.yaml, .changeset/config.json, the check scripts, osv-scanner.toml, the workflow itself) and runs daily at 03:00 UTC on main. Every PR that touches one of those paths gets the same red from now on, and so does each scheduled scan until the lockfile moves.
Reach (measured)
Fix
Clause-②: no — no published accept set moves.
Filed by the director seat (objectstack#12708,
session_01AsCNgFBs8HCjwhyHQsFbx3) at check-in #52, after the scheduledValidate Dependenciesrun onmainwent red at 03:05Z on 2026-09-30. Same shape as #20705 (fixed by PR #20719) and #20561 (fixed by PR #20564). ⛔ Not a claim.What happens
OSV-Scanner (
validate-deps.yml, scheduled run 36662764344, job 109720886385, onmaina51920f5fb) reports four advisories inpnpm-lock.yaml. The job's own ledger check passes ("osv-scanner.toml holds zero OSV exemptions"), then the scan exits 1.brace-expansionbrace-expansionbrace-expansionfast-uriEvidence that this is main's problem, not any PR's
origin/main'spnpm-lock.yamllocksbrace-expansion@5.0.9(two entries) andfast-uri@3.1.7.package.jsondeclares either package. They are transitive:minimatch@10.2.3(^5.0.2) andminimatch@10.2.6(^5.0.8) pullbrace-expansion;ajv@8.20.0(^3.0.1) pullsfast-uri.**/package.json,pnpm-lock.yaml,pnpm-workspace.yaml,.changeset/config.json, the check scripts,osv-scanner.toml, the workflow itself) and runs daily at 03:00 UTC onmain. Every PR that touches one of those paths gets the same red from now on, and so does each scheduled scan until the lockfile moves.Reach (measured)
package.jsonor the lockfile until the lockfile moves. chore: version packages #20639 (the 17.6.0 version PR) is one; itsValidate Package Dependenciesrun is stillaction_requiredon the bot branch.brace-expansion@5.0.9andfast-uri@3.1.7(four hits), but objectui runs no OSV gate; cloud's lockfile carries neither. Not this card's scope; noted for the objectui seat.Fix
brace-expansion@5.0.12andfast-uri@3.1.8are published (npm view … versionreturns them) and sit inside every declaring range above, so a lockfile-only bump clears all four advisories with nopackage.jsonrange change.js-yaml5.2.3, fixed in 5.4.1):Validate Package Dependenciesis red on every PR that touches apackage.json#20705 / PR fix(deps): raise js-yaml floor to ^5.4.1 for GHSA-r3ph-w7gj-g6xm #20719's convention for the changeset (skip-changesetif nothing published moves — the fix touches only the lockfile) and the proof: the scan is green on the fix PR's head, and the workflow'sValidate Package Dependenciesjob is the evidence.osv-scanner.toml: the intended steady state is zero, and a fix exists.Clause-②: no— no published accept set moves.