Skip to content

[finding] main's lockfile carries four advisories on brace-expansion 5.0.9 and fast-uri 3.1.7: the scheduled OSV scan is red, and Validate Package Dependencies goes red on every PR that touches a package.json #20769

Description

@objectstack-fleet

Filed by the director seat (objectstack#12708, session_01AsCNgFBs8HCjwhyHQsFbx3) at check-in #52, after the scheduled Validate Dependencies run on main went red at 03:05Z on 2026-09-30. Same shape as #20705 (fixed by PR #20719) and #20561 (fixed by PR #20564). ⛔ Not a claim.

What happens

OSV-Scanner (validate-deps.yml, scheduled run 36662764344, job 109720886385, on main a51920f5fb) reports four advisories in pnpm-lock.yaml. The job's own ledger check passes ("osv-scanner.toml holds zero OSV exemptions"), then the scan exits 1.

package locked advisory CVSS fixed in
brace-expansion 5.0.9 GHSA-6j4f-fj2g-mc7p 7.5 5.0.10
brace-expansion 5.0.9 GHSA-qhr7-859c-m2p7 7.5 5.0.11
brace-expansion 5.0.9 GHSA-q2hr-2g5m-vwhr 5.3 5.0.12
fast-uri 3.1.7 GHSA-hrr3-gc8f-f4qj 4.8 3.1.8

Evidence that this is main's problem, not any PR's

  • origin/main's pnpm-lock.yaml locks brace-expansion@5.0.9 (two entries) and fast-uri@3.1.7.
  • No workspace package.json declares either package. They are transitive: minimatch@10.2.3 (^5.0.2) and minimatch@10.2.6 (^5.0.8) pull brace-expansion; ajv@8.20.0 (^3.0.1) pulls fast-uri.
  • The job is path-filtered (**/package.json, pnpm-lock.yaml, pnpm-workspace.yaml, .changeset/config.json, the check scripts, osv-scanner.toml, the workflow itself) and runs daily at 03:00 UTC on main. Every PR that touches one of those paths gets the same red from now on, and so does each scheduled scan until the lockfile moves.

Reach (measured)

Fix

Clause-②: no — no published accept set moves.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxpriority:p1High: required for production / M2securitytooling

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions