Skip to content

fix(dev-1713): bump rollup to 4.59.0 - #64

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1713
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1713

Conversation

@spur-vuln-author

Copy link
Copy Markdown

Context

GHSA-mw96-cpmx-2vgc: rollup before 4.59.0 is vulnerable (high severity). Transitive dependency (not declared in any package.json), resolved via pnpm-lock.yaml. No Dependabot PR exists for this finding, so this PR was constructed directly from the advisory's first_patched_version.

Test evidence

No Dependabot PR existed; constructed from first_patched_version 4.59.0. Added a pnpm.overrides entry and regenerated the lockfile with pnpm install --lockfile-only. Two resolutions existed before (4.40.0 and 4.61.1, same major); both now converge on 4.61.1, satisfying >= 4.59.0. Companion-file scan (Dockerfiles, .nvmrc, go.mod, CI workflow YAML, etc. hardcoding 4.40.0) found no hits.

Risk

Low. Lockfile-only transitive dependency bump within the same major version line. GHSA-mw96-cpmx-2vgc / high severity; Tier 1 / 90-day SLA, currently overdue.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Sep 30, 2026
@spur-vuln-reviewer

Copy link
Copy Markdown

Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=rollup manifest=pnpm-lock.yaml pr_version=? required=4.59.0 alerts=35 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new rollup version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 35: 4.59.0. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants