Skip to content

fix(dev-1714): bump zx to 8.8.5 - #72

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1714
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1714

Conversation

@spur-vuln-author

Copy link
Copy Markdown

Context

GHSA-w87r-vg9q-crqm: zx before 8.8.5 is vulnerable (medium severity). zx is pinned via the repo pnpm catalog in pnpm-workspace.yaml (previously 8.4.1), not a per-package specifier, so the fix is a catalog entry bump. No Dependabot PR exists for this finding; constructed directly from the advisory's first_patched_version.

Test evidence

No Dependabot PR existed; constructed from first_patched_version 8.8.5. Bumped the repo catalog's zx entry in pnpm-workspace.yaml from 8.4.1 to 8.8.5 and regenerated the lockfile with pnpm install --lockfile-only. Confirmed via lockfile inspection that zx now resolves to 8.8.5 (previously 8.4.1). Companion-file scan (companion-scan.sh pnpm-lock.yaml 8.4.1) found no stale companion files referencing the old version.

Risk

Low. Lockfile/catalog-only version bump of a devDependency-only CLI scripting tool, no runtime usage in shipped package output. GHSA-w87r-vg9q-crqm / medium severity; Tier 1 / 180-day SLA.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Oct 1, 2026
@spur-vuln-reviewer

Copy link
Copy Markdown

diff-mismatch-constructed: Gate 3 (gate3-check.sh) returned FAIL for this PR.

GATE3 FAIL target=zx manifest=pnpm-lock.yaml pr_version=? required=8.8.5 alerts=21 extra_files=1 extra_direct_deps= state=open companion_files=

Details:

  • The helper has no version-extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not confirm the new zx version actually meets the required 8.8.5 (max first_patched_version across 21 open Dependabot alerts for this package+manifest).
  • The diff also touches pnpm-workspace.yaml, a file outside {manifest, lockfile}, which is not declared as a companion_files entry on this PR's footer.

Not merged. A human must review this. This reviewer will not act on this PR again.
[[spur-vuln-reviewer: escalated diff-mismatch-constructed]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants