Finding
Reader's exact-head CI run for PR #72 failed at pnpm quality → quality:dependencies on high advisory GHSA-ch52-4w7c-c8xp. The upstream advisory lists http-cache-semantics versions <=4.2.0 as affected and currently reports no patched version (<0.0.0).
The audited lockfile path is landing-astro → astro@7.2.8 → http-cache-semantics@4.2.0 (pnpm-lock.yaml, Astro dependency entry and package snapshot). CI run 37236899001 evaluated head 7cf1a38249d5f24cce5c9a1553c5d60d641cbb21; it reported one unexpected high advisory and no critical advisories. The repository's current accepted-advisory list does not include this ID.
Follow-up
Keep the security gate failing. Track upstream patched-release availability, then verify the actual Reader build/runtime reachability and affected call sites before proposing a scoped dependency repair or any qualification. Do not add a waiver, alter the accepted-advisory list, or claim static build output alone proves safety.
Private evidence: .fleet-local/precise-footer-release/security-ghsa-ch52-evidence.json.
Finding
Reader's exact-head CI run for PR #72 failed at
pnpm quality→quality:dependencieson high advisory GHSA-ch52-4w7c-c8xp. The upstream advisory listshttp-cache-semanticsversions<=4.2.0as affected and currently reports no patched version (<0.0.0).The audited lockfile path is
landing-astro→astro@7.2.8→http-cache-semantics@4.2.0(pnpm-lock.yaml, Astro dependency entry and package snapshot). CI run 37236899001 evaluated head7cf1a38249d5f24cce5c9a1553c5d60d641cbb21; it reported one unexpected high advisory and no critical advisories. The repository's current accepted-advisory list does not include this ID.Follow-up
Keep the security gate failing. Track upstream patched-release availability, then verify the actual Reader build/runtime reachability and affected call sites before proposing a scoped dependency repair or any qualification. Do not add a waiver, alter the accepted-advisory list, or claim static build output alone proves safety.
Private evidence:
.fleet-local/precise-footer-release/security-ghsa-ch52-evidence.json.