v1.87.1.0 fix: update vulnerable sharp and adm-zip overrides - #2873
Conversation
|
😎 Merged successfully - details. |
E2E Evals: ✅ PASS0/0 tests passed | $0 total cost | reconcile exit: 0
Fail-closed reconciliationSliced lane: diff-selected gate census via scripts/test-paid-shards.ts (planner → 6 executors → fail-closed report) |
|
Final verification on The paid lane reconciled successfully but executed no selected model cases; its empty/skipped shards provide no additional coverage. Local full-suite environment limitations and unavailable external CLI review remain documented above. |
Addresses #2866. Adapts the dependency-only fix from #2867 onto current main. Contributed by @smsmatt; the override-expiry ledger and scheduled-scan notification proposal remain in that PR.
Update
sharpto 0.35.4 andadm-zipto 0.6.1, including their resolved platform packages, without adding vulnerability exceptions or changing the pinned evaluation harness. Regression tests enforce the fixed version floors, load Sharp, and verify that ordinary archive extraction works while file and directory destination-symlink escapes are rejected.Verification
GHSA-rgj7-g3m4-5g8candGHSA-vwc7-r8mq-g2x9, exit 1. The new regression file has 1 pass and 5 failures with the original lockfile, including both symlink escape cases..osv-scanner.toml, exit 0 with no unsuppressed findings. Three applicable existing exceptions remain; this is not a claim of zero vulnerabilities without exceptions.Owner liveness exemption verified. No compiled binaries, workflow changes, or suppression changes are included.
Documentation
CONTRIBUTING.md: documents the focused dependency-security regression command, fixed-version/runtime and ZIP-extraction checks, Windows symlink-test skips, and the unchanged OSV exception policy.Documentation Debt
docs/cso-scanners.mdanddocs/cso-release-qualification.mdneed navigation links to their existing reference/how-to content.CONTRIBUTING.mdandARCHITECTURE.mdstill describe a dry run rather than the actual all-host generation and tracked-diff/untracked-file checks.docs/BROWSER_INTERNALS.mdsays/sidebar-chatwas removed but also lists it under the tunnel listener; it needs a separate source-grounded documentation correction.Suggested label:
docs-debt. No new public surface lacks documentation, and no new tutorial or page is needed for this dependency patch.