Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz

Relationships

#2722 deno run audit prints No description available for every advisory

Opened by hammz · 9/29/2026· Shipped 9/29/2026

scripts/audit_deps.ts looks up vulnerabilities with POST https://[HOST-1]/v1/querybatch. That endpoint returns only the id and modified timestamp of each matching vulnerability, not its summary or details. So the code at line 232 always falls back to its default text (vuln.summary ?? No description available), and every finding in the terminal output and the GitHub step summary shows no description. Triaging a failing vuln-scan therefore means looking up each GHSA id by hand.

Fix: after the batch query, fetch the full record for each unique vulnerability id with GET https://[HOST-1]/v1/vulns/ID (deduplicated, bounded concurrency, an AbortSignal timeout, and --allow-net is already scoped to [HOST-1]). Then use its summary, falling back to the first line of details.

This was raised as a side note on swamp-club#2720, which is being closed as a duplicate of swamp-club#2719 (the js-yaml bump that fixed the failing audit). This issue carries the description problem forward.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 9 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/29/2026, 7:38:17 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
hammz assigned hammz9/29/2026, 6:58:56 PM

Sign in to post a ripple.