Relationships
#2720 deno task audit fails on main: new OSV advisories in locked dependencies block verify-build
Opened by stack72 · 9/29/2026
deno task audit (the vuln-scan step of the verify-build verification workflow) exits 1 on a clean checkout of origin/main at f0dbe34d, as of 2026-09-29 around 19:30 UTC. Because vuln-scan is part of the attestation gate, gate.allPassed is false for every branch until it is fixed, whatever the branch changes.
Found while verifying swamp-club#2700. That branch does not touch deno.json or deno.lock.
The audit reports OSV advisories, all printed as "No description available", against locked dependencies including:
- hono@4.13.0
- undici@7.29.0
- ws@8.20.0
- fast-uri@3.1.4
- ip-address@10.2.0
- js-yaml@4.3.0
- qs@6.15.2
- sharp@0.34.5
- socket.io-parser@4.2.6
- adm-zip@0.5.18
- brace-expansion@5.0.8
- csv-parse@7.0.1
- @ai-sdk/provider-utils@4.0.30
Several PRs merged earlier today with passing attestations, so these advisories look newly published (or newly returned by [HOST-1]) rather than introduced by a change.
To reproduce, run git worktree add --detach /tmp/audit origin/main, then cd /tmp/audit && deno task audit. It exits 1.
Needed: bump the affected dependencies, or triage the advisories that do not apply to how swamp uses them. The empty descriptions are worth a look too, since scripts/audit_deps.ts may not be reading the summary field OSV now returns.
Closed
No activity in this phase yet.
hammz commented 9/29/2026, 6:52:43 PM
Closing as a duplicate of swamp-club#2719. The only thing making the audit exit 1 was js-yaml 5.3.0, a dependency packages/dashboard pulls in directly (GHSA-r3ph-w7gj-g6xm). scripts/audit_deps.ts only fails on vulnerable direct dependencies. For packages pulled in indirectly (hono, undici, ws, sharp and the rest listed here) it prints a warning and does not change the exit code. PR https://github.com/swamp-club/swamp/pull/2705 (merged as 3b80e3de) bumped js-yaml to 5.4.2, and a clean worktree of origin/main now runs deno run audit with exit 0. The empty-description problem you spotted is real: the OSV querybatch endpoint returns only advisory ids. It is now tracked separately as swamp-club#2722.
Sign in to post a ripple.