Skip to content

fix(dev-1715): bump glob to 10.5.0 - #67

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1715
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1715

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

GHSA-5j98-mcp5-4vw2: glob before 10.5.0 is vulnerable (high severity). Transitive dependency (not declared in any package.json), resolved via pnpm-lock.yaml. No Dependabot PR exists for this finding, so this PR was constructed directly from the advisory's first_patched_version.

Test evidence

No Dependabot PR existed; constructed from first_patched_version 10.5.0. Three separate glob resolutions coexisted (10.4.5, 11.0.2, 7.2.3) from unrelated consumers — a blanket override would have wrongly forced the unaffected 11.x consumer down. Used pnpm's scoped override syntax ("glob@<10.5.0": "^10.5.0") so only dependents actually requesting glob below 10.5.0 are affected. Regenerated the lockfile with pnpm install --lockfile-only. Confirmed via lockfile inspection that the 10.x and former-7.x resolutions now converge on glob@10.5.0, while the unrelated glob@11.0.2 resolution is untouched. Companion-file scan (Dockerfiles, .nvmrc, go.mod, CI workflow YAML, etc. hardcoding 10.4.5) found no hits.

Risk

Low. Scoped lockfile-only transitive dependency bump; deliberately does not touch the unrelated glob@11 consumer. GHSA-5j98-mcp5-4vw2 / high severity; Tier 1 / 90-day SLA, currently overdue.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Sep 30, 2026
@spur-vuln-reviewer

Copy link
Copy Markdown

Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=glob manifest=pnpm-lock.yaml pr_version=? required=11.1.0 alerts=18,20 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new glob version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 18,20: 11.1.0. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants