Skip to content

Track GHSA-ch52 in Astro dependency tree #73

Description

@sarthakagrawal927

Finding

Reader's exact-head CI run for PR #72 failed at pnpm quality → quality:dependencies on high advisory GHSA-ch52-4w7c-c8xp. The upstream advisory lists http-cache-semantics versions <=4.2.0 as affected and currently reports no patched version (<0.0.0).

The audited lockfile path is landing-astro → astro@7.2.8 → http-cache-semantics@4.2.0 (pnpm-lock.yaml, Astro dependency entry and package snapshot). CI run 37236899001 evaluated head 7cf1a38249d5f24cce5c9a1553c5d60d641cbb21; it reported one unexpected high advisory and no critical advisories. The repository's current accepted-advisory list does not include this ID.

Follow-up

Keep the security gate failing. Track upstream patched-release availability, then verify the actual Reader build/runtime reachability and affected call sites before proposing a scoped dependency repair or any qualification. Do not add a waiver, alter the accepted-advisory list, or claim static build output alone proves safety.

Private evidence: .fleet-local/precise-footer-release/security-ghsa-ch52-evidence.json.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions