Repository navigation
fix(deps): take the fixes for proxy-addr, source-map-js and katex that turn main's OSV scan red - #21951
Conversation
…jqcg-44mw-7w3h and GHSA-68fv-2mgg-jv7q Both fixed versions are admitted by every parent's declared range (express ^2.0.7; postcss, @tailwindcss/node, css-tree, magicast ^1.2.1), so the lockfile only had to move off the two vulnerable resolutions. Done through a temporary override pair, installed and then removed, so no other resolution moved (11 insertions, 11 deletions); a plain `pnpm update -r --depth Infinity` re-resolved eleven unrelated packages and was rejected. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude <noreply@anthropic.com>
No published mermaid admits the fixed line (11.16.1 declares ^0.16.45; 11.17.0 through 12.1.0 declare ^0.16.47), so this is an override past the dependent's declared range, not a dedupe. The selector follows the overrides block's header rule: floor at the advisory's 0.11.0, bound at the 0.19.0 caret boundary of the target line. The target resolves to 0.18.10 because npm deprecates 0.18.11. mermaid's only katex call (renderToString with throwOnError, displayMode and output) renders MathML through 0.18.10 in Chromium. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude <noreply@anthropic.com>
…ut the katex entry The note claimed the gate lists katex as an override it cannot cross-check. Measured on this tree, it says nothing about the entry: nothing publishable declares katex, mermaid consumes it, and the selector's bound clears the target floor, so neither census reports it. Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw Co-authored-by: Claude <noreply@anthropic.com>
|
Correction to this PR's body, from the The body says the local scan used "OSV-Scanner v2.3.8, the version Corrected reading: the local scans were measured with OSV-Scanner v2.3.8 and v2.5.0 (the image the CI job pulls). Both give identical rows on every tree. The verdicts in the body are unchanged. Generated by Claude Code |
Part of #21945
Clause-②: no
What this does
Validate Package Dependenciesruns OSV-Scanner againstpnpm-lock.yaml. Onmainit reports four advisories, so the scheduled scan is red, and so is every PR that touches apackage.json. Three of the four name a fixed version, and this PR takes those three fixes. The fourth,sprintf-js, has no fixed release. Its[[IgnoredVulns]]entry is on branchclaude/issue-21945-osv-exemption, in its ownosv-exemptionPR, as convention 3 inosv-scanner.toml's header requires.Which half this leaves: GHSA-hp3w-g68c-fv3c (
sprintf-js). This PR alone does not turn the OSV step green, and neither does the exemption PR alone. The card stays open when this PR merges, and the PM finishes it after both have landed.OSV reading: before and after
Measured locally with OSV-Scanner v2.3.8, the version
validate-deps.ymlpins.api.osv.devanswers 403 from this container, so the scan ran in offline mode (--offline-vulnerabilities --download-offline-databases) against the OSV npm database the scanner downloaded on 2026-10-06.mainatd16b9fbf(exit 1). These are the same four rows the scheduled run 37407261685 reported:This PR at
e142f120(exit 1, one row left, which the exemption PR covers):This PR's lockfile scanned with the exemption PR's
osv-scanner.toml: exit 0,No issues found, with one vulnerability filtered.Changes
pnpm-lock.yaml:proxy-addr2.0.8 andsource-map-js1.2.2Every parent's declared range already admits the fix:
express5.2.1 declaresproxy-addr ^2.0.7, andpostcss8.5.28,@tailwindcss/node4.3.3,css-tree3.2.1 andmagicast0.5.3 declaresource-map-js ^1.2.1. So this is a re-lock and needs no new pin.pnpm update proxy-addr source-map-js -r --depth Infinity. It re-resolved unrelated packages:@inquirer/*,@napi-rs/wasm-runtime,node-abi, a secondpostcss,nanoidandip-addresscopy, andknex's peer set. That was +81/−60 lines.proxy-addrto 2.0.8,source-map-jsto 1.2.2), installed and then removed, followed by a second install. The lockfile keeps the two resolutions and nothing else moves: +11/−11 lines, the two package entries and the five dependent edges.pnpm-workspace.yamlends that step byte-identical tomain.pnpm-workspace.yamloverrides:pluspnpm-lock.yaml:katexto^0.18.2pnpm-workspace.yaml. The rootpackage.jsonhas nopnpm.overrides(itspnpmfield holds onlyignoredBuiltDependencies), and the block's own header records that pnpm v10 reads overrides from this file.'katex@>=0.11.0 <0.19.0': '^0.18.2'. The floor is the advisory'sintroduced(0.11.0), and the bound sits at the caret boundary of the 0.18 target line. That is the durable shape the block header andcheck:override-consistencydescribe: the bound sits above the target's line, so a later lift moves only the target.^0.18.2resolves to 0.18.10, not 0.18.11, because npm deprecates 0.18.11 ("Accidentally published with breaking changes. Use 0.19.0 instead."). katex 0.18's CLI dependency movescommander8.3.0 to 15.0.0, which was already in the tree, socommander@8.3.0drops out. Lockfile +6/−11.mermaidadmits the fix. Measured withnpm view mermaid@V dependencies.katex: 11.16.0 and 11.16.1 declare^0.16.45, and 11.17.0, 11.17.1, 11.17.2, 12.0.0 and 12.1.0 (latest) declare^0.16.47. This override forces mermaid past its own declared range, so it needs evidence that mermaid still works.Totals:
pnpm-lock.yaml+17/−22;pnpm-workspace.yaml+33/−0 (one entry plus its note).Evidence that katex 0.18 works for the only consumer
The only path to katex is
apps/docs, thenmermaid^11.16.0(11.16.1), thenkatex. Nothing else in the workspace names katex (git grep -i katex, lockfile excluded: zero hits).renderKatexUnsanitizedindist/chunks/mermaid.core/chunk-I66GZJ75.mjs. That is a lazyimport("katex")followed bykatex.renderToString(c, { throwOnError: true, displayMode: true, output }), whereoutputis"mathml"or"htmlAndMathml". The katex 0.17 and 0.18 breaking changes (the internal__defineFunctionAPI, and the prefixed internal CSS classes) touch neither that call nor the outer.katexclass mermaid styles (.node .katex path). The 0.19.0 strict-mode change is outside the target line.katex.versionis0.18.10, andrenderToStringwith mermaid's options returns MathML for both output modes.mermaid@11.16.1mermaid.core.mjsran in headless Chromium with the sameinitialize()optionsapps/docs/components/mermaid.tsxpasses (securityLevel: 'strict'). It rendered a flowchart whose label is$$x^2 + \frac{a}{b}$$with this result:{"katexVersion":"0.18.10","hasMath":true,"hasMsup":true,"hasFrac":true,"unsupported":false,"errored":false,"pageErrors":[]}.next buildinapps/docsran under the shared verify lock (VERDICT command-exit 0; compiled in 119s; 1240/1240 static pages;BUILD_IDwritten). The client chunk carries katexversion:"0.18.10", and no0.16.47remains in.next/static/chunks. This wasnext buildalone, not the fullvercel.jsoncommand: the docs app reads onlypackages/spec/package.jsonfrom the spec, and the committedcontent/docs/referencesstood in forgen:schema/gen:docs. The PR'sBuild Docsjob runs the production command.Object.prototype.trust,\href{…}{x}through katex 0.16.47 emits a link, and through 0.18.10 it does not.No page in
content/puts$$inside a mermaid block today, so this path is latent rather than live. The proof is still of the code that would run.Changeset
skip-changeset. The diff touchespnpm-lock.yamlandpnpm-workspace.yaml, both repo-root configuration. Neither is in any package'sfiles[], and overrides do not reach downstream installs, so nothing publishes.Local verification, at
e142f120pnpm install --frozen-lockfile --prefer-offline: exit 0.node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackat this head: 22 commands, the same list the dispatch named. The--ranreconciliation is filled in below.check:override-consistency: green. katex appears in neither census: mermaid consumes it, and the bound clears the target floor.--ranreconciliation, with exit codes recorded before any pipe: 22 derived, 18 run, 4 NOT-MEASURED, 0 UNRUN.node scripts/check-changeset-fixed.mjsnode scripts/check-closing-keyword-parity.mjs(+--self-test)node scripts/check-comment-mask-corpus.mjsnode scripts/check-dts-emitted.mjs --self-testnode scripts/check-osv-exemptions.mjs(+--self-test)node scripts/check-prerelease-pin-watch.mjs --self-test;--verbosepnpm --filter @objectstack/spec run check:llms-txtpnpm check:driver-memory-census·check:gitlink-declared·check:nul-bytes·check:override-consistency·check:refd-timer-probe·check:vendor-export-contract-resolve·check:watch-hint-literal·check:workspace-manifest-cyclespnpm check:dts-closure·check:dual-build-cjs-loads·check:lean-entry-closure·check:sourcemap-no-sources-contentNOT MEASURED (four gates). They read every package's built
dist/. This diff touches no package source, so the local scope builds no package, and the build these four need is the fullpnpm build. CI'sBuild CoreandLint & Repo Gatesmeasure them on the built tree. Both NOT MEASURED readings are declared here and are not counted as passes.Not run locally, CI's: the path-scheduled jobs
dispatch-gateslists (Test Core,Temporal Conformance,Dogfood Regression Gate,Dogfood Verify CLI,Build Core,Build Docs) and the type-check lanes.Acceptance notes
pnpm installprintsioredis-mock 8.13.1: unmet peer ioredis@^5: found 6.0.0. That warning is already present onmain: the lockfile there resolves the same pair, andpackages/services/service-cluster-redis/src/ioredis-pair.pin.test.tspins it. It is not from this diff.Generated by Claude Code