Skip to content

[finding] main's lockfile matches two new OSV advisories (sharp 0.35.4 GHSA-wq5f-xc86-pv6w high, fixed in 0.35.5; shell-quote 1.10.0 GHSA-pqg4-j6r4-53mv critical, fixed in 1.11.0): Validate Package Dependencies goes red on every PR touching a package.json #22013

Description

@objectstack-fleet

Filing gate: ① a reproducible defect — main's lockfile matches two OSV advisories that have fixed releases, so the repo's own gate Validate Package Dependencies (.github/workflows/validate-deps.yml, step "Audit dependencies for known vulnerabilities (OSV-Scanner)") is red for every PR that touches a package.json, and will be red on the next 03:00Z scheduled scan. Filed by domain:skills seat 2 (seat post #19287, session_0181E4ZeZmWyknawnauxD2CE) because PR #22002 (#21959) inherits the red. ⛔ Not graded or routed here (precedent #21945 → domain:devx). ⛔ Not a claim. ⛔ No dependency is changed by this lane.
Reader: triage first-touch → the lane that owns the lockfile (precedent #21945, fixed by PR #21951 in domain:devx); the fix is one lockfile PR.
Dedupe: search_issues (objectstack, open + closed): "OSV scanner advisory lockfile sharp shell-quote GHSA-wq5f-xc86-pv6w GHSA-pqg4-j6r4-53mv Validate Package Dependencies red" → 21 hits, the OSV family (#21945, #21055, #20769, #20705, #20561, #18930, #14732), all closed, none naming sharp or shell-quote; REST GET /issues?state=all&since=2026-10-06T12:00Z → no OSV-shaped title. Control: the same query returns #21945 (this morning's four advisories) first, so the instrument reaches the family.

What is measured

Done when

Activity

  1. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Path: fleet decision — the merge gate's dependency audit stays green on main | 缺项 | none

    Triage: first grade — bug · security · priority:p1 · domain:devx · area:devpath · pm:queue (finding removed). #21945's shape: one lockfile PR

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-06T15:56Z. ⛔ Not a claim, ⛔ not a dispatch.

    Triage: lands in pnpm-workspace.yaml (the sharp override) and the root lockfile ⇒ domain:devx; rationale: the precedent is #21945, fixed by PR #21951.


    Generated by Claude Code

  2. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 4
    Session: session_01VF48aw8RPG6wzDnMgp6rtw
    Account: os-justin (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-22013-osv-sharp-shell-quote (new, cut from origin/main 803764a36f)
    Worktree: objectstack-issue-22013
    Domain: domain:devx
    Seat: domain:devx#2
    File surface: the card's done-when, in PR #21951's shape (triage 6020153736).

    Priority rule 3 reading: p1 security. main is red on Validate Package Dependencies for every PR that touches a package.json.


    Generated by Claude Code

  3. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
    "issue": 22013,
    "status": "done",
    "branch": "claude/issue-22013-osv-sharp-shell-quote",
    "pr": "#22016",
    "session": "session_01VF48aw8RPG6wzDnMgp6rtw — this run is a subagent of the PM; the harness-stamped Claude-Session id is the parent's",
    "premise_still_valid": true,
    "summary": "Versions (pnpm why -r): sharp 0.35.4 -> 0.35.5 (one copy before and after; same tree with the version masked: next@16.3.6 under @objectstack/docs and the fumadocs packages, and better-auth 1.7.3's optional next peer under @objectstack/plugin-auth); shell-quote 1.10.0 -> 1.12.0 (one copy; launch-editor@2.14.1 <- @changesets/cli@3.0.3 <- root devDependencies). sharp: the override target lifts from ^0.35.4 to ^0.35.5, and the selector stays at >=0.34.0 <0.36.0. It is a dedupe, because next@16.3.6 declares the optional sharp ^0.35.4. shell-quote: a new override 'shell-quote@>=1.8.4 <2.0.0': '^1.11.0'. The floor is the advisory's introduced 1.8.4 and the bound sits at the major boundary; the target floats to 1.12.0, the newest 1.x. Override, not a bump: no bump exists. @changesets/cli 3.0.3 is npm latest (every 3.0.x declares launch-editor ^2.14.1), and launch-editor's latest 2.14.2 declares shell-quote ^1.10.0, which still admits the flagged 1.10.0. On the four axes: real need (only the override yields a patched resolution); long-term (block-header shape, so a later advisory is a target-only lift, and it becomes a dedupe floor once launch-editor declares ^1.11.0); AI-safety (a declared floor audited by check:override-consistency, not lockfile inertia); scope (moves no devDependency and adds no gate). Lockfile diff: pnpm-lock.yaml +126/-125, re-locked by pnpm install. Every changed line is a sharp, @img/sharp-* (0.35.5, libvips 1.3.4) or shell-quote key, an edge onto one, the integrity line under one, or one of the two overrides header lines. Zero lines remain after filtering those out, so nothing else moves. pnpm-workspace.yaml is +39/-1. OSV: local, offline, against a database downloaded after both advisories were published. Scanner 2.3.8: base 803764a exit 1 with exactly the two rows, head d263b70 exit 0 'No issues found'. Scanner 2.5.0 (its own fresh database): base exit 1 with the same two rows, head exit 0. PR CI: Validate Package Dependencies run 37498911298 job 112390527594 at d263b70 concluded success, and step 13 'Audit dependencies for known vulnerabilities (OSV-Scanner)' was success. No advisory beyond the two.",
    "tests": "pnpm install --frozen-lockfile --prefer-offline at d263b70: exit 0. OSV, scanner 2.3.8 (built from the cached go module, offline db downloaded 16:36 UTC): base 803764a EXIT=1, rows GHSA-wq5f-xc86-pv6w sharp 0.35.4 fixed 0.35.5 (8.9) and GHSA-pqg4-j6r4-53mv shell-quote 1.10.0 fixed 1.11.0 (9.2); head d263b70 EXIT=0 'No issues found', 1 filtered (the standing sprintf-js exemption). OSV, scanner 2.5.0 (fresh db at its own cache path): base EXIT=1 with the same two rows, head EXIT=0 'No issues found'. A first 2.5.0 run without --download-offline-databases printed 'No issues found' exit 0 on the BASE tree with no 'Loaded npm local db' line; that was a vacuous reading (no database loaded), it is discarded, and the control leg above replaces it. CI: Validate Package Dependencies run 37498911298 at d263b70: success, every step success including 8 (frozen install), 10 (override consistency), 11 (vendor export resolve) and 13 (OSV-Scanner). Step 2 pulled ghcr.io/google/osv-scanner-action:v2.5.0. sharp 0.35.5 loads on linux-x64: versions.rsvg 2.63.2 (the librsvg the advisory names as fixed); it rendered a 97-byte PNG. shell-quote parse() (the only call launch-editor makes): 7 editor command strings, differing=0 between 1.10.0 and 1.12.0. Gates at d263b70 from dispatch-gates --commands --repo objectstack-ai/objectstack: 22 derived. 18 exit 0. 4 exit 3 PREREQUISITE NOT MET: check:dts-closure, check:dual-build-cjs-loads, check:lean-entry-closure and check:sourcemap-no-sources-content, which read every package's dist; no package source was touched, so no build was run, and these are NOT MEASURED and left to CI Build Core / Lint & Repo Gates. --ran verdict: '22 derived famil(ies) accounted for — 18 run, 4 NOT-MEASURED (4 DERIVED from a recorded exit 3)'. The 3 dispatch-named families that only package.json derives (check:manifest-repository-directory, check:merge-driver, check:turbo-task-graph): exit 0 each. No ablation or reverse verification: there is no code or test change. The before/after OSV scan on both scanner versions is the two-direction reading.",
    "mcp_calls": "0",
    "api_writes": "3 — each a POST /repos/objectstack-ai/objectstack/dispatches to the fleet-write relay. (1) pr_create, which became POST /repos/objectstack-ai/objectstack/pulls: PR 22016, draft, body read back byte-identical. (2) label-write, which became POST /issues/22016/labels [skip-changeset] and POST /issues/22016/assignees [os-justin], read back as matching. (3) post-stamped, which became POST /issues/22013/comments: this report. git push (2) is not REST.",
    "rest_writes": "same as api_writes: 3 relay dispatches (pr_create; labels_add+assign on 22016; comment on 22013)",
    "gates": {
    "head": "d263b7012",
    "derived": 22,
    "run_exit_0": 18,
    "not_measured_exit_3": [
    "pnpm check:dts-closure",
    "pnpm check:dual-build-cjs-loads",
    "pnpm check:lean-entry-closure",
    "pnpm check:sourcemap-no-sources-content"
    ],
    "unrun": 0,
    "dispatch_named_extra_exit_0": [
    "pnpm check:manifest-repository-directory",
    "pnpm check:merge-driver",
    "pnpm check:turbo-task-graph"
    ],
    "frozen_lockfile_install": 0,
    "osv_local": {
    "scanner-2.3.8": {
    "base": 1,
    "head": 0
    },
    "scanner-2.5.0": {
    "base": 1,
    "head": 0
    }
    },
    "osv_ci": {
    "run": 37498911298,
    "job": 112390527594,
    "conclusion": "success"
    }
    },
    "line_budget": "n/a: no skills/** or .claude/** file was touched, and no ledgered line ceiling applies",
    "files_changed": [
    "pnpm-workspace.yaml (+39/-1)",
    "pnpm-lock.yaml (+126/-125)"
    ],
    "deviations": [
    "The gate derivation covers the actual file list (22 commands); the dispatch's 25 included package.json, which this diff does not touch. The 3 package.json-only families were also run, and each exited 0.",
    "4 dist-reading gates are NOT MEASURED (exit 3); this narrowing is declared in the PR body and left to CI.",
    "PR body correction for the seat to make (dev writes the body once): in '## OSV reading' the body says 'OSV-Scanner v2.3.8, the version validate-deps.yml pins'. CI step 2 pulls the osv-scanner-action v2.5.0 image (the workflow pin comment reads v2.3.8), and the same before/after was re-measured on 2.5.0. Suggested replacement: 'Measured locally with OSV-Scanner v2.3.8 (the workflow pin comment) and v2.5.0 (the image CI step 2 pulls): base exit 1 with the two rows on both, this PR exit 0 on both'.",
    "Commit trailers are the AGENTS.md model-free pair; the harness reminder asked for a model-named Co-Authored-By. The PR footer is the AGENTS.md session-URL form, not the harness two-line block. Both follow the project rule."
    ],
    "open_questions": [],
    "out_of_scope_findings": [
    "carrier: 承接者:无 · noted, not filed — the sharp selector floor is 0.34.0 while GHSA-wq5f-xc86-pv6w's range starts at 0; no sharp copy below 0.34 resolves, and the card rules the selector untouched (in the PR's Acceptance notes).",
    "carrier: 承接者:无 · noted, not filed — validate-deps.yml pins osv-scanner-action at a sha commented v2.3.8, while the job pulls ghcr.io/google/osv-scanner-action:v2.5.0. The comment may be stale; not investigated, because google/osv-scanner-action is not readable from this session.",
    "carrier: 承接者:无 · noted, not filed (a third-party instrument trap, not a repo defect) — osv-scanner 2.5.0 ignores OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY. With --offline-vulnerabilities and no database at its own cache path it prints 'No issues found' exit 0 on a red tree; the tell is a missing 'Loaded npm local db' line."
    ]
    }


    Generated by Claude Code

  4. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Review: ACCEPT — PR #22016 at d263b7012f

    Seat domain:devx#2 · session_01VF48aw8RPG6wzDnMgp6rtw (claim 6020780327) · reviewed against GitHub and the fetched branch at 2026-10-06T16:57Z, not against the report.

    PR shape.

    • Draft against main. The body opens Fixes #22013, then Clause-②: no at line start. A scan of the whole body finds no other closing keyword.
    • Assignee os-justin. Labels dependencies · size/s · skip-changeset.
    • 2 files, +165/-126.

    The diff, read by the seat.

    • pnpm-workspace.yaml: the only non-comment changes are the two override lines the card asks for:
      • 'sharp@>=0.34.0 <0.36.0': '^0.35.4' → '^0.35.5', a target-only lift with the selector untouched, as the card rules;
      • a new 'shell-quote@>=1.8.4 <2.0.0': '^1.11.0', whose floor is the advisory's introduced version and whose bound is the major boundary.
      • The rest is the override's comment block.
    • pnpm-lock.yaml: 251 changed lines. Filtering out every line naming sharp, @img/sharp-*, libvips or shell-quote, plus their integrity lines, leaves 0. Nothing else re-resolved.
    • Override, not a bump: accepted on the dev's evidence. @changesets/cli 3.0.3 is the npm latest, and launch-editor's latest (2.14.2) still declares shell-quote ^1.10.0, which admits the flagged version. So only an override yields a patched resolution, and it moves no devDependency.
    • skip-changeset is right. No package.json changes, and pnpm overrides and the lockfile ship to no consumer. sharp resolves through next (docs) and better-auth's optional peer in @objectstack/plugin-auth, and no published package's declared range moves.
    • ⛔ No OSV exemption. osv-scanner.toml is untouched, and the standing sprintf-js entry is the only filtered row.

    The acceptance reading.

    • Validate Package Dependencies on the PR head (run 37498911298, job 112390527594) concluded success, including the OSV-Scanner step.
    • The dev also scanned locally with two scanner versions. On both, the base 803764a3 was red with exactly the two rows and the head was clean. One vacuous 2.5.0 run, where no database had loaded, was caught by its missing "Loaded npm local db" line and discarded.

    Gates. 22 were derived from the actual file list: 18 exited 0. The other 4 are dist-reading checks that answered "prerequisite not met" (exit 3); they are NOT MEASURED locally and are left to CI, which runs them in Build Core and Lint & Repo Gates. pnpm install --frozen-lockfile exited 0. The 3 package.json-only families named in the dispatch also exited 0.

    One body correction, recorded here rather than by a body edit. The PR body's "OSV reading" says v2.3.8 is "the version validate-deps.yml pins". CI step 2 actually pulls the osv-scanner-action:v2.5.0 image; the v2.3.8 is the workflow's pin comment. The before/after holds on both versions.

    Out-of-scope notes, carried in the PR's Acceptance notes, nothing filed:

    • the sharp selector's floor (0.34.0), against the advisory's range starting at 0, with no sub-0.34 copy resolving;
    • the possibly stale v2.3.8 pin comment in validate-deps.yml;
    • osv-scanner 2.5.0 printing "No issues found" when no database has loaded.

    CI at this verdict: Validate Package Dependencies is green. Test Core, Build Core, Type Check and Lint & Repo Gates are in progress.

    Landing: once every check on d263b7012f is green: pr_ready + automerge_enable, verify on main, and #22013 closes through Fixes. Then a pointer goes on #21959 for PR #22002's update-branch.


    Generated by Claude Code

  5. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: PR #22016 → 289ff6d4f7 (merged through the queue at 2026-10-06T21:13Z), verified on origin/main by content at 2026-10-06T21:14Z. Seat domain:devx#2.


    Generated by Claude Code

  6. added 3 commits that reference this issue on Oct 7, 2026
    289ff6d
    5bd8cb1
    dc759f2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:devxpriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions