Skip to content

fix(dev-1700): bump @humanfs/node to 0.16.8 - #57

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1700
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1700

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

GHSA-p498-v437-472g: @humanfs/node before 0.16.8 is vulnerable (medium severity). This is a transitive dependency (not declared in any package.json) resolved via pnpm-lock.yaml. No Dependabot PR exists for this finding, so this PR was constructed directly from the advisory's first_patched_version.

Test evidence

No Dependabot PR existed; constructed from first_patched_version 0.16.8. Added a pnpm.overrides entry for @humanfs/node and regenerated the lockfile with pnpm install --lockfile-only. Confirmed via lockfile inspection that @humanfs/node now resolves to 0.16.8 (previously 0.16.6) in both resolution entries. Companion-file scan (Dockerfiles, .nvmrc, go.mod, CI workflow YAML, etc. hardcoding 0.16.6) found no hits.

Risk

Low. Lockfile-only transitive dependency bump, no direct consumer in this repo's own source. GHSA-p498-v437-472g / medium severity; Tier 1 / 180-day SLA.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Sep 30, 2026
@spur-vuln-reviewer

Copy link
Copy Markdown

Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=@humanfs/node manifest=pnpm-lock.yaml pr_version=? required=0.16.8 alerts=112 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new @humanfs/node version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 112: 0.16.8. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants