Repository navigation
fix(dev-1695): bump js-yaml to 4.3.2 - #69
spur-vuln-author[bot] wants to merge 1 commit into
Conversation
|
Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=js-yaml manifest=pnpm-lock.yaml pr_version=? required=4.3.2 alerts=16,19,84,85,86,88,103,108,120,121 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new js-yaml version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 16,19,84,85,86,88,103,108,120,121: 4.3.2. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]] |
Context
Batched group (ticket_group_key
tg:js-yaml:pnpm-lock.yaml, 5 advisories) againstjs-yaml, all inpnpm-lock.yaml:Transitive dependency (not declared in any package.json), resolved via
pnpm-lock.yaml. No Dependabot PR exists for any of these, so this PR was constructed directly from the highestfirst_patched_versionacross the group (4.3.2).Test evidence
No Dependabot PR existed; constructed from first_patched_version 4.3.2 (highest across the batch). Two separate js-yaml resolutions coexisted (3.14.1 and 4.1.0) from unrelated consumers — these advisories only affect the 4.x line (GHSA range floors start at 4.1.1). A naive
"js-yaml@<4.3.2"override scope initially also swept up the 3.x consumer (converting it to 4.x, a real breaking-change risk for that unrelated dependent), so the override was tightened to"js-yaml@>=4.0.0 <4.3.2": "^4.3.2"to only affect the 4.x line. Regenerated the lockfile withpnpm install --lockfile-only. Confirmed via lockfile inspection that the 4.x resolution now resolves to4.3.2exactly (previously4.1.0), satisfying >= 4.3.2 for all five advisories, while the 3.x consumer drifted only within its own major (3.14.1 → 3.15.2, a normal patch-level re-resolution, untouched by the override). Companion-file scan (Dockerfiles,.nvmrc,go.mod, CI workflow YAML, etc. hardcoding4.1.0) found no hits.Risk
Low. Scoped lockfile-only transitive dependency bump within the 4.x major line only; the unrelated js-yaml@3 consumer is deliberately untouched. Group max severity high; Tier 1 / 90-day SLA, currently overdue.