Skip to main content
← Back to list
01Issue
BugClosedSwamp CLIPublic
AssigneesNone

Relationships

#2720 deno task audit fails on main: new OSV advisories in locked dependencies block verify-build

Opened by stack72 · 9/29/2026

deno task audit (the vuln-scan step of the verify-build verification workflow) exits 1 on a clean checkout of origin/main at f0dbe34d, as of 2026-09-29 around 19:30 UTC. Because vuln-scan is part of the attestation gate, gate.allPassed is false for every branch until it is fixed, whatever the branch changes.

Found while verifying swamp-club#2700. That branch does not touch deno.json or deno.lock.

The audit reports OSV advisories, all printed as "No description available", against locked dependencies including:

Several PRs merged earlier today with passing attestations, so these advisories look newly published (or newly returned by [HOST-1]) rather than introduced by a change.

To reproduce, run git worktree add --detach /tmp/audit origin/main, then cd /tmp/audit && deno task audit. It exits 1.

Needed: bump the affected dependencies, or triage the advisories that do not apply to how swamp uses them. The empty descriptions are worth a look too, since scripts/audit_deps.ts may not be reading the summary field OSV now returns.

02Bog Flow
✓OPEN○TRIAGED○IN PROGRESS◉CLOSED

Closed

9/29/2026, 6:52:43 PM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

hammz commented 9/29/2026, 6:52:43 PM

Closing as a duplicate of swamp-club#2719. The only thing making the audit exit 1 was js-yaml 5.3.0, a dependency packages/dashboard pulls in directly (GHSA-r3ph-w7gj-g6xm). scripts/audit_deps.ts only fails on vulnerable direct dependencies. For packages pulled in indirectly (hono, undici, ws, sharp and the rest listed here) it prints a warning and does not change the exit code. PR https://github.com/swamp-club/swamp/pull/2705 (merged as 3b80e3de) bumped js-yaml to 5.4.2, and a clean worktree of origin/main now runs deno run audit with exit 0. The empty-description problem you spotted is real: the OSV querybatch endpoint returns only advisory ids. It is now tracked separately as swamp-club#2722.

Sign in to post a ripple.