Repository navigation
fix(deps): clear sharp, source-map-js, postcss-selector-parser and smol-toml osv advisories - #943
Merged
Merged
Conversation
…ol-toml osv advisories Four advisories published after #941 now fail the dependency scan on main and in the merge queue: - GHSA-wq5f-xc86-pv6w (8.9) sharp 0.35.4 -> 0.35.5 - GHSA-68fv-2mgg-jv7q (8.7) source-map-js 1.2.1 -> 1.2.2 - GHSA-rj75-hqrm-r3gf (5.9) postcss-selector-parser 6.1.4 -> 7.1.6 - GHSA-r4xh-jqrq-34v2 (5.3) smol-toml 1.8.0 -> 1.9.0 Raise the sharp floor and add resolutions floors for the other three; the lockfile change is these four entries plus sharp's per-platform @img binaries. All four are docs-build transitives (astro, expressive-code, postcss/css-tree, knip). postcss-selector-parser has no fixed 6.x, so it crosses a major under postcss-nested ^6; the docs build output is byte-identical before and after (202 files). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
krokoko
approved these changes
Oct 6, 2026
krokoko
enabled auto-merge
October 6, 2026 16:52
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 6, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 6, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 6, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 6, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 6, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 7, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Oct 7, 2026
isadeks
added a commit
to isadeks/sample-autonomous-cloud-coding-agents
that referenced
this pull request
Oct 8, 2026
Bring in aws-samples#912 (optional network stack, 490-resource budgets, compute_types) and aws-samples#943. Beyond the conflict resolutions: - gate MicroVM resources on compute_types; keep the nested-stack and suspend gates - reapply runtime env and grant changes inside the optional AgentCore block; the SessionRole keeps the approval tables - extend SessionRole and orchestrator overflow nag exceptions to the continuation prefix and the MicroVM image version suffix - census profiles select the nested MicroVM layout and an artifact digest; every inline profile now fits, so the expected rejections are removed - disable console test-invoke on the approval-request API - deduplicate the vault keys both branches added to the platform-config contract and its fixtures - map the developer-guide budgets subsection to its split page so the stricter link check passes - tests count MicroVM resources across nested stacks Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears the four OSV findings that now fail the dependency scan on
mainand in the merge queue. They ejected #912 from the queue. All four advisories were published after #941 merged, so this isn't a regression: the advisory database changed under an unchanged lockfile.Area
tooling— rootmise.toml, scripts, CI workflowsRelated
yarn.lockChanges
package.jsonresolutions: raised the existingsharpfloor to^0.35.5and added floors forpostcss-selector-parser ^7.1.6,smol-toml ^1.9.0andsource-map-js ^1.2.2. None of the four are in jira-forge-app's lockfile, so nooverridesmirror is needed, andcheck-transitive-pin-syncstays green.yarn.lock: re-resolved only these entries, plus sharp's per-platform@img/sharp-*binaries, which always move with sharp. This follows the approach from fix(deps): clear devalue and basic-ftp osv advisories #935 and fix(deps): clear the http-cache-semantics osv advisory #941.All four are docs-build transitives. sharp, smol-toml and source-map-js stay inside their dependents' existing ranges (
astro,@astrojs/internal-helpers,knip,postcss,css-tree,magicast).postcss-selector-parser crosses a major version, so it needs a reviewer's look. It's transitive through
postcss-nested@^6←@expressive-code/core@^0.44.0, which requests^6.1.1. The advisory has no fixed 6.x release.postcss-nested8.x itself depends on^7.1.4. To check for behaviour changes, I built the docs before and after: the output is byte-identical (202 files, CSS included).Testing
osv-scanner scan --lockfile agent/uv.lock --lockfile yarn.lock --lockfile integrations/jira-forge-app/package-lock.json→ No issues foundmise run drift-preventionpassesmise //docs:buildpasses, anddocs/distis byte-identical to the build frommainPushed with
--no-verify: the local pre-push hook fails on the three existingsilent-success-maskingfindings in files this PR doesn't touch, as noted in #941. This change only touchespackage.jsonandyarn.lock.🤖 Generated with Claude Code