Repository navigation
fix(dev-1712): bump minimatch to 3.1.3 - #68
spur-vuln-author[bot] wants to merge 1 commit into
Conversation
|
Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=minimatch manifest=pnpm-lock.yaml pr_version=? required=10.2.3 alerts=37,38,40 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new minimatch version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 37,38,40: 10.2.3. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]] |
Context
GHSA-7r86-cg39-jmmj:
minimatchbefore 3.1.3 is vulnerable (high severity, ReDoS). Transitive dependency (not declared in any package.json), resolved viapnpm-lock.yaml. No Dependabot PR exists for this finding, so this PR was constructed directly from the advisory'sfirst_patched_version.Test evidence
No Dependabot PR existed; constructed from first_patched_version 3.1.3. Three separate minimatch resolutions coexisted (10.0.1, 9.0.5, 3.1.2) from unrelated consumers — a blanket override would have wrongly forced the unaffected 9.x/10.x consumers down to 3.x. Used pnpm's scoped override syntax (
"minimatch@<3.1.3": "^3.1.3") so only dependents actually requesting minimatch below 3.1.3 are affected. Regenerated the lockfile withpnpm install --lockfile-only. Confirmed via lockfile inspection that the 3.x resolution now resolves to3.1.5(previously3.1.2), satisfying >= 3.1.3, whileminimatch@9.0.5andminimatch@10.0.1are untouched. Companion-file scan (Dockerfiles,.nvmrc,go.mod, CI workflow YAML, etc. hardcoding3.1.2) found no hits.Risk
Low. Scoped lockfile-only transitive dependency bump; deliberately does not touch the unrelated minimatch@9/minimatch@10 consumers. GHSA-7r86-cg39-jmmj / high severity; Tier 1 / 90-day SLA, currently overdue.