Repository navigation
fix(dev-1707): bump tmp to 0.2.6 - #58
spur-vuln-author[bot] wants to merge 1 commit into
Conversation
|
Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=tmp manifest=pnpm-lock.yaml pr_version=? required=0.2.6 alerts=7,68 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new tmp version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 7,68: 0.2.6. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]] |
Context
GHSA-ph9p-34f9-6g65:
tmpbefore 0.2.6 is vulnerable (high severity, arbitrary file/directory write via symlink). Transitive dependency (not declared in any package.json), resolved viapnpm-lock.yaml. No Dependabot PR exists for this finding, so this PR was constructed directly from the advisory'sfirst_patched_version.Test evidence
No Dependabot PR existed; constructed from first_patched_version 0.2.6. Added a
pnpm.overridesentry and regenerated the lockfile withpnpm install --lockfile-only. Confirmed via lockfile inspection thattmpnow resolves to0.2.7(previously0.0.33), satisfying >= 0.2.6. Companion-file scan (Dockerfiles,.nvmrc,go.mod, CI workflow YAML, etc. hardcoding0.0.33) found no hits.Risk
Medium — large version jump for a 0.x package (0.0.33 → 0.2.7), but
tmpis a small, widely-used temp-file utility with no direct usage in this repo's own source (dev-tooling transitive only). GHSA-ph9p-34f9-6g65 / high severity; Tier 1 / 90-day SLA, currently overdue.Note: this same bump also resolves the low-severity sibling advisory GHSA-52f5-9888-hmc6 on the same package/manifest, tracked separately as a risk-accept-proposal in DEV-1708 (that ticket is left as-is per policy — the risk-acceptance record stands even though the fix incidentally lands here).