Repository navigation
fix(dev-1715): bump glob to 10.5.0 - #67
spur-vuln-author[bot] wants to merge 1 commit into
Conversation
|
Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=glob manifest=pnpm-lock.yaml pr_version=? required=11.1.0 alerts=18,20 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new glob version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 18,20: 11.1.0. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]] |
Context
GHSA-5j98-mcp5-4vw2:
globbefore 10.5.0 is vulnerable (high severity). Transitive dependency (not declared in any package.json), resolved viapnpm-lock.yaml. No Dependabot PR exists for this finding, so this PR was constructed directly from the advisory'sfirst_patched_version.Test evidence
No Dependabot PR existed; constructed from first_patched_version 10.5.0. Three separate glob resolutions coexisted (10.4.5, 11.0.2, 7.2.3) from unrelated consumers — a blanket override would have wrongly forced the unaffected 11.x consumer down. Used pnpm's scoped override syntax (
"glob@<10.5.0": "^10.5.0") so only dependents actually requesting glob below 10.5.0 are affected. Regenerated the lockfile withpnpm install --lockfile-only. Confirmed via lockfile inspection that the 10.x and former-7.x resolutions now converge onglob@10.5.0, while the unrelatedglob@11.0.2resolution is untouched. Companion-file scan (Dockerfiles,.nvmrc,go.mod, CI workflow YAML, etc. hardcoding10.4.5) found no hits.Risk
Low. Scoped lockfile-only transitive dependency bump; deliberately does not touch the unrelated glob@11 consumer. GHSA-5j98-mcp5-4vw2 / high severity; Tier 1 / 90-day SLA, currently overdue.