Skip to content

Validate Package Dependencies is red on main — 8 FIXABLE OSV advisories (undici / hono / fast-uri), so every PR inherits a red required-ish check #5032

Description

@xuyushun441-sys

Found while shipping #4762 (PR #5027) — filed unassigned, not fixed there (that PR touches packages/lint only and adds no resolved package).

Symptom

The Validate Package Dependencies job (.github/workflows/validate-deps.ymlgoogle/osv-scanner-action, --lockfile=pnpm-lock.yaml) fails on PR #5027 with:

Total 4 packages affected by 8 known vulnerabilities (0 Critical, 2 High, 6 Medium, 0 Low, 0 Unknown) from 1 ecosystem.
8 vulnerabilities can be fixed.

| OSV URL                             | CVSS | PACKAGE  | VERSION | FIXED VERSION |
| https://osv.dev/GHSA-7p8r-x3mc-p8w7 | 7.5  | fast-uri | 3.1.4   | 3.1.5         |
| https://osv.dev/GHSA-8j4g-w8fx-2239 | 5.3  | hono     | 4.12.32 | 4.12.34       |
| https://osv.dev/GHSA-8j4g-w8fx-2239 | 5.3  | hono     | 4.12.33 | 4.12.34       |
| https://osv.dev/GHSA-4cwx-7wf7-3272 | 7.4  | undici   | 7.28.0  | 7.29.0        |
| https://osv.dev/GHSA-8xcm-r25x-g524 | 4.8  | undici   | 7.28.0  | 7.29.0        |
| https://osv.dev/GHSA-jr45-8vmc-qm54 | 5.9  | undici   | 7.28.0  | 7.29.0        |
| https://osv.dev/GHSA-m8rv-5g2x-5cg5 | 4.2  | undici   | 7.28.0  | 7.29.0        |
| https://osv.dev/GHSA-v3r7-h72x-cjcm | 4.8  | undici   | 7.28.0  | 7.29.0        |
Exit code: 1

It is main's state, not the PR's

PR #5027's entire pnpm-lock.yaml delta is three lines — an importer entry adding an already-resolved ajv@8.20.0 to packages/lint. No new package is resolved. And every flagged package/version is present on origin/main verbatim:

$ for p in "fast-uri@3.1.4" "hono@4.12.32" "hono@4.12.33" "undici@7.28.0"; do
    printf '%-18s on origin/main: ' "$p"
    git show origin/main:pnpm-lock.yaml | grep -q "^  $p:" && echo PRESENT || echo absent
  done
fast-uri@3.1.4     on origin/main: PRESENT
hono@4.12.32       on origin/main: PRESENT
hono@4.12.33       on origin/main: PRESENT
undici@7.28.0      on origin/main: PRESENT

So every open PR branched off current main inherits this red check, and the signal is now uninformative: a PR that does introduce a vulnerable dependency looks exactly like one that does not. That is the failure mode a permanently-red gate always has.

The last scheduled run of this workflow on main (2026-08-03, 832047c5) was green, so the advisories are recent and/or arrived with the last day's merges (hono moved to 4.12.33 with #5006). Nothing is wrong with the gate itself — it is reporting a true fact.

Distinct from #4965

#4965 asks how the OSV gate should express an advisory with no fix available. This is the opposite case: the scanner says plainly "8 vulnerabilities can be fixed", and names the fixed version for each. So the answer here is a dependency bump, not a policy decision — but it does want doing deliberately, because two of the three are transitive.

What needs deciding / doing

  • hono — a direct dependency (@objectstack/plugin-hono-server, adapters). Bump to ^4.12.34. Two versions are resolved (4.12.32 and 4.12.33), so whatever pins the older one needs finding too.
  • undici — transitive. Needs a pnpm-workspace.yaml override (or an upstream bump) to >=7.29.0; note scripts/check-override-consistency.mjs gates that overrides resolve to their targets, so the override must be added the way that script expects.
  • fast-uri — transitive via ajv. Override to >=3.1.5.

Acceptance: pnpm exec osv-scanner --lockfile=pnpm-lock.yaml (or the workflow) exits 0 on main, and pnpm check:override-consistency stays green.

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions