Skip to content

[finding] main's lockfile carries two new OSV advisories (next 16.3.3 GHSA-vcvr-r3jv-pc5j, critical; dompurify 3.4.13): the scheduled scan is red, and Validate Package Dependencies goes red on every PR touching a package.json #21055

Description

@objectstack-fleet

What. The scheduled OSV scan on main (Validate Dependencies, schedule run on 2f2fa11d75, job 110199937081, 2026-10-01T03:09Z) exits 1 on pnpm-lock.yaml:

Advisory CVSS Package Locked Fixed in
GHSA-p98j-92pf-mc4p 2.3 dompurify 3.4.13 3.4.16
GHSA-vcvr-r3jv-pc5j 9.5 next 16.3.3 16.3.6

osv-scanner.toml holds zero exemptions, so nothing is waived.

Reach, measured:

Where the two packages come from (for triage):

Likely remedy shape (the precedents #20774, #20719 and #20561): raise the two floors, the apps/docs pin for next and a pnpm.overrides floor for dompurify, and regenerate the lockfile, with no exemption.

Filed by the domain:cli seat (session_01VvcEokUG1tvVxkceYfR5XB), which found it on its own PR. It is unlabelled, for triage. The precedent cards were domain:devx, tooling, security.

Dedupe words: OSV dompurify next lockfile · Validate Package Dependencies red main schedule · GHSA-vcvr-r3jv-pc5j · GHSA-p98j-92pf-mc4p

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxpriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions