Repository navigation
Bump the application-delivery lock to Next.js 16.3.6 for GHSA-vcvr-r3jv-pc5j - #252
Merged
Merged
Conversation
…jv-pc5j Next.js 16.3.6 (tag commit a758ffc, published 2026-09-22, not a prerelease) fixes GHSA-vcvr-r3jv-pc5j / CVE-2026-94545, a critical remote code execution in next/og ImageResponse that affects >= 16.2.0 < 16.3.6. Because it is a security fix, it takes the urgent-fix exception instead of waiting out the 7-day cooldown. rg over the whole repository finds no next/og, ImageResponse or @vercel/og use, and app/ serves a static icon.svg. The fixture never reached the vulnerable path; the bump takes the vulnerable package out of the lock. - package.json: next 16.3.5 -> 16.3.6. pnpm-lock.yaml was regenerated with the fixture's own pnpm 12.4.2. Only next, @next/env and the eight @next/swc-* entries change, and all ten integrities equal registry.npmjs.org dist.integrity for 16.3.6. - history/recipe-revisions.json keeps the 16.3.5 files under history/ with their receipt hashes, following the Makefile/serve.py pattern, and records the source review and the checks that passed: frozen install, pnpm peers check, pnpm typecheck and the production build. The PostgreSQL, API and browser stages were not rerun, so the 2026-09-20 receipt still qualifies 16.3.5 only. - manifests/stack.json, the saturation-audit row and the landscape upstream-snapshot record move to 16.3.6 / a758ffc. The snapshot record comes from a fresh run of the same four gh api endpoints. The evidence hashes are updated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
…lock experiment.json's frozen_inputs bind pnpm-lock.yaml by path and sha256. validate_convergence --all-recorded failed once the lock moved to 16.3.6. The record's pnpm-lock input now names the byte-identical retained copy history/pnpm-lock.0472177.yaml. The frozen hash and every other byte of the record are unchanged, and the experiment still qualifies only the 16.3.5 lock it ran with. The original experiment.json is kept as history/experiment.json.0472177. A name without a .json suffix keeps it out of convergence record discovery, like Makefile.cabbe2c. recipe-revisions.json records the relocation, and a new portability test checks it: the retained bytes, the current hash, the path as the only change, and the target lock's hash. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 of 7 tasks
seathatflowsinourveins
added a commit
that referenced
this pull request
Oct 6, 2026
) ### Scope Fix the newly reviewed advisories that blocked every required OSV check: target only fsspec 2026.6.0/multidict 6.9.1 in the OpenHands runtime lock, Mako 1.4.2 in the application Python lock, and source-map-js 1.2.2 in its pnpm lock. Preserve all other package pins and the original captured artifact bytes. The command center selected a dated source-backed exception for the frozen macOS input in its isolated config, and exclusion of both retired Lumibot lockchecks after the owner's confirmation. Each lock has native before/after evidence and its supported installation/qualification checks. No workflow or branch-protection setting changes. - Base: `ecfa112764c664d35377dd66b8cfcb67e5a94d60` (fetch confirmed current main). - Lane: `lane:foundation`. - Owned scope: three production locks, SDK pins/research/evidence, qualification and ruling receipts, bounded OSV configuration/inventory, existing binding/no-use guards and closure record. Evidence registry committed last. ## SOTA sources - [fsspec advisory GHSA-27vj-qcqg-25rc](GHSA-27vj-qcqg-25rc), [official 2026.6.0 release metadata](https://pypi.org/pypi/fsspec/2026.6.0/json), [maintainer tag](https://github.com/fsspec/filesystem_spec/tree/2026.6.0). - [multidict advisory GHSA-54p9-h82j-f925](GHSA-54p9-h82j-f925), [official 6.9.1 release](https://github.com/aio-libs/multidict/releases/tag/v6.9.1), [PyPI metadata](https://pypi.org/pypi/multidict/6.9.1/json). - [Mako advisory GHSA-5639-2j2p-m4mx](GHSA-5639-2j2p-m4mx), [maintainer release](https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2), [official metadata](https://pypi.org/pypi/Mako/1.4.2/json). - [source-map-js advisory GHSA-68fv-2mgg-jv7q](GHSA-68fv-2mgg-jv7q), [published 1.2.2 metadata](https://registry.npmjs.org/source-map-js/1.2.2), [maintainer fix PR79](7rulnik/source-map-js#79). - Dependent ranges: [Hugging Face Hub0.35.3](https://pypi.org/pypi/huggingface-hub/0.35.3/json), [aiohttp3.14.3](https://pypi.org/pypi/aiohttp/3.14.3/json), [yarl1.22.0](https://pypi.org/pypi/yarl/1.22.0/json), [Alembic1.20.0](https://pypi.org/pypi/alembic/1.20.0/json), [PostCSS8.5.23](https://registry.npmjs.org/postcss/8.5.23). Complete declared-parent checks include optional/null metadata handling; limitations remain explicit in receipts. - [#562 at74cc5468](#562): original builder/relock/hash/install/scan/guard pattern. Installed [uv0.12.22](https://github.com/astral-sh/uv/releases/tag/0.12.22) reproduces the accepted baseline byte for byte; #562's0.12.17 remains historical. - [#587 at798ac445](#587), [#252 atc96c2555](#252): bounded frontend qualification. [pnpm12.4.2 update parser](https://github.com/pnpm/pnpm/blob/9502f3c457717dae3a4ddbf4315a8c4aee16fdb4/pnpm/crates/cli/src/cli_args/update.rs) and [supported update docs](https://pnpm.io/cli/update): selective bare-name transitive update, no-save/lockfile-only; obsolete explicit-version/Infinity forms avoided. - Frozen config precedent [8fc8611](8fc8611) and the maintained closure at `docs/decisions/2026-09-22-github-automation-closure.md`. Indexed source offsets/reconstruction inspected at [source-map-js1.2.1](https://github.com/7rulnik/source-map-js/blob/428d49f6b1e1614f082b7706fa879a3d9c64f728/lib/source-map-consumer.js#L944). Dedicated input/digest/expiry guards retained. - Trial [#336 at20b52a5b](#336), existing captured XNYS exclusion precedent, and command-center ruling `task-ns2604-coop-20261006T003954Z`. The verified owner confirmation is a **report** row: `report-native-agent-stack-5f-20261006T0045Z-osv`, from `native-agent-stack-5f`, at `2026-10-06T00:41:23Z`, replying to `task-native-agent-stack-5f-20261006T004011Z`. Sanitized evidence: `evidence/receipts/osv-captured-lumibot-lockchecks-20261005.json`. No trial replay or new host-process census is claimed. ### Evidence-class table | Claim | Class | Actual result | | --- | --- | --- | | Published dependent ranges permit the fixes | source_review | Complete pinned metadata review; no caps/errors; exact parents linked above | | Targeted locks preserve other pins | local_integration | SDK byte-identical control; only two package blocks move. Mako only package block, native lock revision3→5 recorded. pnpm manager/importers unchanged; only source-map-js move | | Release identity and supported artifact hashes match | local_integration | Native hash checks0: fsspec2, multidict14, Mako2; universal wheels/sdist included | | Supported isolated/native qualification succeeds | local_integration | SDK178-package check/imports0; backend28-package check/import/render0; frontend frozen install/peers/typecheck/build0 | | Both required scan partitions pass locally | local_integration | Before:60ordinary/1frozen,5+1 unignored findings. After:58ordinary/1frozen, actual native exits0/0, zero unignored findings | | Binding/coverage/no-use guards remain effective | local_integration / synthetic |70 touched tests0; clean control0; all deliberate negative controls1 as expected | | Registry integrity | local_integration | validate.py0;69components/4profiles/212receipts/10309hashes; integrity only | | Hosted, image, provider and full API/browser acceptance | unknown | No claim; command-center exact-head cross-family read remains pending | ### Local commands run All heavy phases used nice19; scratch/cache and installs were isolated. Exact supported commands and sanitized actual returned output/hashes are retained in the three relock prefixes and linked receipts. ``` #562-pattern paired native uv control/targeted lock/check/export:0 native release hash checks:0 hashed SDK install / uv pip check / exact imports:0 targeted Mako lock/check; frozen/no-build sync; pip check; imports/render:0 pnpm12.4.2 update source-map-js --no-save --lockfile-only --ignore-scripts:0 pnpm install --frozen-lockfile --ignore-scripts; peers check; typecheck; build:0 python -m unittest tests.test_openhands_lock_binding tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use 70 tests; latest final data-pin run6.936s; exit0 OSV2.6.0 ordinary scan:0; frozen scan:0 python3 scripts/validate.py:0,10309hashes component_matrix --write:0,32rows/zero flips new_host_grand_list --write:0,32layers/66winners git diff --check and git diff --cached --check:0 ``` ### Failed conditions The initial root-added UV_NO_CONFIG1 discarded the resolver's Linux workspace settings; the next copied formatter inserted two plus signs. Native lock/check/export succeeded in both, while the relock byte-comparison script failed. Neither candidate was adopted; both are disclosed separately. Test preflight rejected inside-checkout TMPDIR before execution; existing external lane cache was used. Intermediate stale receipt/unreviewed metadata-line guards failed before being corrected. Publication caught one private interpreter path in a negative-control trace; it was sanitized. Terminal progress whitespace was normalized and its capture hash rebound. No failure is promoted to a passing upstream test. ### Decision record `docs/decisions/2026-09-22-github-automation-closure.md`, "Four production relocks and preserved receipt inputs (2026-10-06)"; SDK research section and qualification/ruling receipts record alternatives, source/replay limits and overturn conditions. The macOS exception expires2026-12-24; its `.frozen` rename is a separate follow-up. Future use of captured trial dependencies requires a separately maintained/scanned qualification environment. ### Host evidence No evidence/hosts or platform-status flip. The native runtime imports/builds are local integration; source reviews, synthetic controls and hosted acceptance remain separate. Exact-head command-center review is requested. ### Checklist - [x] No workflow/action permission or branch-protection change. - [x] No credential value or authentication store read/printed/copied; no new required secret. - [x] No paid hosting, provider/model runtime call, deployment or restart. - [x] Peer-owned worktrees preserved; three captured locks remain byte-identical. - [x] Registry committed last; one lane:foundation label. - [x] Ordinary AND frozen native scans and touched tests passed before ready. - [ ] Command-center exact-head cross-family read and 5f landing; lane never merges. ## Dated input-binding repair (2026-10-06) The command-center exact-head read of67c6594d2 found two omitted downstream gates: both convergence records still resolved their original UV digest through the newly relocked live file, and the recipe ledger's PNPM current digest was stale. This amendment preserves trial evidence instead of attributing new dependencies to the original runs. - Retain ecfa112 UV/PNPM bytes and the two pre-amendment experiment snapshots byte-for-byte. - Change only each canonical record's UV input path; keep frozen digests, commands, observations, outputs and usage. Both records remain declared. - Append dated recipe supersession/current mappings and ordered path relocations; protect original/prior/superseded bytes and all non-path record bytes with the portability assertions. - Source: [#252 path-only relocation](https://github.com/seathatflowsinourveins/native-agent-stack/blob/c96c2555c2d84683d9e519623354c814aeb6a584/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L121) and [#587 supersession](https://github.com/seathatflowsinourveins/native-agent-stack/blob/798ac445307e2cd8eba6e74d7722ac0e16da02c7/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L99). - Dated decision/source receipt: `docs/decisions/2026-10-06-application-input-binding-amendment.md`, `evidence/receipts/pr765-bindings-amendment-20261006.json`. Before repair, all-recorded convergence exited1 (2invalid/32) and native-maintenance exited1 (29cases/one PNPM mismatch). Repaired focused checks: native-maintenance29passed; convergence/OSVcoverage/frozenMAC102passed. After main-registry refresh and full own-file re-registration, local validate0/10315hashes and all-recorded convergence0/32valid. Full local suite ran under A22's specific copied-fixture `install.sh --list` exception and exited1:10,343tests/2217.568s,18failures/18errors/905skips. Installer apply paths remain banned. Raw output is retained privately; known systemd parser (#767), missing calendar/mutation imports, PATH fixtures, token-canary fixtures and installed Windows Terminal type drift are recorded separately, never presented as a pass. Old reviewed head's hosted baseline was6/7 required contexts: validate failed, six others passed. Required acceptance is measured at the new pushed head; no workflow rerun loop or old local check is promoted into that acceptance. No production pin, recorded trial output, raw receipt, frozen macOS lock, captured trading lock or scanner exclusion changed in this repair.
5 of 7 tasks
seathatflowsinourveins
added a commit
that referenced
this pull request
Oct 6, 2026
### Scope Patch the live application recipe's sharp 0.35.4 dependency to the first fixed release 0.35.5 for GHSA-wq5f-xc86-pv6w. Its required Sharp/@img family moves with it; the captured macOS lock stays byte-identical under one file-scoped exception expiring 2026-12-24. - Base commit: `0d5e6506434fab598dee861c749a22e628beb75a`. - Lane: `lane:foundation`. - Owned paths: live application pnpm lock, retained prior lock and recipe history, bounded qualification outputs, dedicated frozen-macOS exception, its coverage test, dated decision, qualification receipt and evidence registry. - `.github/osv-scanner.toml` and `.github/osv-scanner-lockfiles.json` are byte-identical to the base. The frozen variant retains SHA-256 `f1c707b8295e85bd396e49b990de92dc82bc0d58eca1e4e4bef31262d9898cd2`. ## SOTA sources - [Sharp maintainer advisory GHSA-wq5f-xc86-pv6w](GHSA-wq5f-xc86-pv6w), published 2026-10-06T13:43:57Z: affected `<0.35.5`, first patched `0.35.5`, librsvg CVE-2026-96889. - [Sharp v0.35.5 release](https://github.com/lovell/sharp/releases/tag/v0.35.5), published 2026-09-27T13:44:22Z, `lovell/sharp@51a990faa26ade5586a4934ac9673c98d8893326`; [sharp-libvips v1.3.4](https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4) supplies librsvg 2.63.2. - [pnpm supported targeted update](https://pnpm.io/cli/update) and [frozen-lockfile installation](https://pnpm.io/cli/install), read 2026-10-06; installed pinned pnpm 12.4.2 help/error rejects a versioned selector on an indirect dependency. Published latest and the resulting resolved version were independently checked as exactly 0.35.5; no override or package.json edit was needed. - [Next 16.3.8 published metadata](https://registry.npmjs.org/next/16.3.8): its `optionalDependencies.sharp` range `^0.35.4` permits 0.35.5. This is the lock's only direct dependent on sharp. All 27 replacement resolution integrity values match published npm metadata; 67 unrelated package entries, importers and the pnpm manager document remain unchanged. - [Sharp source at the prior pin](https://github.com/lovell/sharp/blob/7f1a0a22cc285fe180766f4935d50b55af6e8432/src/common.cc#L323), `src/common.cc:323,506,596`, and `src/pipeline.cc:48`: SVG file/buffer input can reach librsvg. Exception justification rests on the retained variant having no supported installer/build/server/replay consumer found in scoped source review, with removal before any manual replay or new consuming route; the macOS label is not itself a reachability exemption. - Repository conventions: `native-agent-stack@0d5e650:blueprints/convergence-practice/application-delivery/Makefile:3-5,27-32`, `README.md:170-180`; [#765](#765), [#587](#587) and [#252](#252) retain prior bytes/qualifications and append supersessions. Original full-stack receipts and canonical experiment records remain untouched. ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | First patched release, dependent range and SVG reachability | source_review | Maintainer advisory/release, pinned source and published npm metadata above | | Exact frozen install, peers, typecheck, production build, loaded sharp/librsvg versions | local_integration | `relock-2026-10-06-sharp.*.txt`; `evidence/receipts/sharp-0355-qualification-20261006.json` | | Frozen byte identity, retained old live lock and bounded family-only changes | local_integration | Hash/source comparisons and recipe revision ledger; 27 replacements / 67 unrelated unchanged | | Repository integrity and declared-record consistency | local_integration | Validator, 32 convergence records and 96 touched tests pass; these do not establish upstream or live application acceptance | | Advisory present for sharp 0.35.4 and absent for 0.35.5 | source_review | Supported OSV version-query API; this is not a native scanner or full-inventory scan | | Complete application/API/browser qualification | local_integration, failed | `make verify` exits 2 on 12 dedicated-PostgreSQL setup errors; browser attempt exits 1 on occupied configured port 18080, with no browser case executed | | Required hosted OSV and other CI checks | pending | Must be observed at this PR's head; no local scanner executable was found in the inspected locations | ### Local commands run Frontend commands below ran in the live application directory, using the recipe's pinned pnpm 12.4.2 through Corepack, task-private cache/store/state/temp paths and a public-registry-only npmrc; heavy commands ran one at a time at nice 19. `relock-2026-10-06-sharp.sh.txt` records the supported replay pattern. Worktree/state path prefixes are sanitized in public outputs. ```text corepack pnpm update sharp --no-save --lockfile-only --ignore-scripts exit 0; exact resolved sharp 0.35.5 checked corepack pnpm install --frozen-lockfile --ignore-scripts exit 0 corepack pnpm peers check exit 0 corepack pnpm typecheck exit 0 corepack pnpm build exit 0 node -e 'const r=require("module").createRequire(require.resolve("next/package.json"));const s=r("sharp");console.log(JSON.stringify({sharp:s.versions.sharp,vips:s.versions.vips,rsvg:s.versions.rsvg}));if(s.versions.sharp!=="0.35.5"||s.versions.rsvg!=="2.63.2")process.exit(1)' exit 0; sharp 0.35.5, vips 8.18.7, rsvg 2.63.2 nice -n 19 python3 scripts/validate.py exit 0; 69 components, 4 profiles, 214 receipts, 10,345 hashed files nice -n 19 python3 scripts/validate_convergence.py --all-recorded --json exit 0; all 32 records valid nice -n 19 python3 -m unittest tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use tests.test_native_maintenance exit 0; 96 tests, repeated after the new files were staged git diff --check exit 0 git diff --cached --check exit 0 after explicit output whitespace sanitization ``` ### Failed attempts and acceptance limits - `pnpm update sharp@0.35.5 --no-save --lockfile-only --ignore-scripts` exits 1 with `ERR_PNPM_UPDATE_VERSION_ON_INDIRECT_DEP`, before mutation. The supported unversioned indirect update resolves exactly the independently verified first patch; no override is added. - A single-document PyYAML read exits 1 because pnpm 12 stores two YAML documents; upstream `safe_load_all` corrects the comparison. - First `make verify` exits 2 because pnpm is not on PATH. Supported Corepack enable creates only task-private shims. The second unchanged run passes schema/type/build checks on supported Python 3.13.16, then exits 2 on 12 PostgreSQL connection-timeout setup errors. The full actual failed log is retained privately and its decisive counts/cause in the public receipt. No PostgreSQL build, container/image pull or global installer was introduced. - Separate unchanged `pnpm test:e2e` exits 1 because port 18080 is occupied and Playwright's recipe refuses reuse. No other owner's service was stopped and no test was relaxed. Full-stack acceptance remains unfinished. - Initial staged diff checking found three trailing build-progress spaces. They were trimmed with that sanitization explicitly recorded, their hashes re-registered and the check repeated. Actual private output remains retained. - Native full-inventory OSV execution and unchanged upstream tests are unclaimed. The database's zero finding for the fixed version does not replace the required hosted scanner verdict. ### Decision record `docs/decisions/2026-10-06-sharp-live-relock-frozen-variant.md` records the targeted patch, rejected broad-ignore/historical-rewrite alternatives and evidence boundaries. Remove or re-review the frozen exception before replay, a new consumer, changed bytes or 2026-12-24. Registry is committed last. Independent bounded source/scope critic accepted this separation; co-op GPT micro-check and command-center exact-head ACK are requested. PR stays draft for that read; 5f owns landing. ### Host evidence No `evidence/hosts/` change or platform-status claim. - [ ] Host-receipt validation: not applicable. - [ ] Command-center exact-head review requested; no platform status flip. ### Checklist - [x] No workflow/action change; existing pinned actions and permissions stay untouched. - [x] No secrets are printed, logged or committed; no new required secret. - [x] No paid hosting or billing surface. - [x] Peer-owned paths, services and worktrees preserved. - [x] Frozen evidence remains byte-identical; registry last; no merge or settings change. ### Review follow-up — 2026-10-06 The co-op relays CC item `task-ns2604-coop-20261006T170124Z`, ruling 2: accept the disclosed browser gap for this urgent security landing conditional on a fresh frozen install/frontend build and restoration of the unrelated Mako JSON escape spelling. Both fresh frontend commands passed. `make postgres-init` exits 2 (inner 127) because the recipe's `.runtime/postgresql/18.6/bin/initdb` is missing. The recipe's `postgres-install` source-build target was not run under the upstream-never-rebuild and park rules. Playwright fixes both service and base URLs to port 18080, held by the local alert service; the service is untouched. No new browser cases ran. Source: `native-agent-stack@4f32d59:blueprints/convergence-practice/application-delivery/Makefile:3-5,27-32,34-58` and `playwright.config.ts:8-16`; original Mako row at base `0d5e6506`. Full sanitized argv, return codes, actual outputs and classes are in `evidence/receipts/sharp-review-followup-20261006.json` and `relock-2026-10-06-sharp.review-*.txt`. Actual returned output remains privately durable; public progress whitespace/EOF normalization is explicit. The original qualification receipt and production/frozen locks stay byte-identical to the reviewed head. ```text pnpm 12.4.2 install --frozen-lockfile (task-private cache/store/state/public-registry config) exit 0; lock current, resolution skipped, 26ms NEXT_TELEMETRY_DISABLED=1 pnpm build exit 0; Next 16.3.8 production build make postgres-init exit 2; missing .runtime/postgresql/18.6/bin/initdb, inner 127 nice -n 19 python3 -m unittest tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use tests.test_native_maintenance exit 0; 96 tests, 8.999s nice -n 19 python3 scripts/validate.py exit 0; 69 components, 4 profiles, 214 receipts, 10,349 hashed files ``` Both original literal Mako `\u2192` spellings now exactly match the base row; parsed values are unchanged. Dated unfinished follow-up after the tools window: qualify the dedicated test DB through an upstream-supported release path and run the unchanged browser recipe in an isolated network namespace if no supported port override exists. Frontend build is not a browser/image-response or exploit test. Independent bounded source critic accepts the repair and separation. New-head co-op micro-check/CC ACK and hosted checks still required; registry is committed last. No broad ignore, alert-service takeover, source build, host configuration or merge.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Next.js v16.3.6 fixes GHSA-vcvr-r3jv-pc5j (CVE-2026-94545). The advisory is critical: remote code execution in
next/ogImageResponse, affecting>= 16.2.0 < 16.3.6. The release was published 2026-09-22T17:15:10Z at tag commita758ffcf501f6f1ddb03175bd1033508424c261eand is not a prerelease. Because this is a security fix, it takes the urgent-fix exception instead of waiting out the 7-day cooldown.Exposure.
rg -n --hidden "next/og|ImageResponse|@vercel/og"over the whole repository returns no matches, and the same search in agent-ecosystem also finds nothing. The fixture'sapp/serves a staticicon.svg, so it never reached the vulnerable path. The bump takes the vulnerable package out of the lock.What changed
blueprints/convergence-practice/application-delivery/package.json:next16.3.5 -> 16.3.6.pnpm-lock.yaml: regenerated with the fixture's own pnpm 12.4.2 (pnpm install --lockfile-only --ignore-scripts).next,@next/envand the eight@next/swc-*entries change.integrityvalues equalregistry.npmjs.orgdist.integrityfor 16.3.6.next@16.3.6declares the same dependency and peer ranges as 16.3.5.history/recipe-revisions.json: keeps the 16.3.5package.jsonandpnpm-lock.yamlunderhistory/with their receipt hashes, following the existing Makefile/serve.py pattern. It records the source review and the checks below. The README gets a short note.manifests/stack.json, thesaturation-audit.jsonrow and thecatalogs/landscape/upstream-snapshot.jsonrecord move to 16.3.6 /a758ffc.gh apiendpoints.manifests/evidence.jsonhashes are updated.experiment.json(a recorded convergence experiment) boundpnpm-lock.yamlby path and hash, sovalidate_convergence --all-recordedfailed once the lock moved. Itsfrozen_inputs.sources[4]now names the byte-identical retainedhistory/pnpm-lock.0472177.yaml; the frozen hash and every other byte are unchanged. The original record is kept ashistory/experiment.json.0472177. Without a.jsonsuffix it stays out of record discovery, likeMakefile.cabbe2c. A new portability test checks that the path is the only change.sources.json,receipt.jsonandfreeze.jsonare unchanged. Withexperiment.json, they still describe the 2026-09-20 acceptance of 16.3.5.Evidence (Mac arm64, Node 24.21.0, pnpm 12.4.2)
pnpm install --frozen-lockfile --ignore-scripts: passed.pnpm peers check: no issues.pnpm typecheck: passed.NEXT_TELEMETRY_DISABLED=1 pnpm build: passed; 3 static routes.test_portability.py: 6 tests OK. It now also verifies the two new retained-file mappings and the relocated frozen input.validate.py,host_receipts.py validate,validate_catalogs.py,validate_foundation.py,landscape.py,build_ecosystem.py --check,component_matrix.py --check,new_host_grand_list.py --check,build_verdicts.py --check,gap_crosswalk.py build --check,gap_wave_ledger.py --check,validate_convergence.py --all-recorded,audit_reports.py --checkandevidence_manifest.py --check.python3 -m unittest: 5072 tests, 2 failures. Both also fail on unmodifiedmainon this Mac, and both are local-environment issues:--record-host(Match the user name as a whole token in host_receipts.sanitize() #227).Gaps
make verifywas not rerun at 16.3.6 (PostgreSQL build, API tests and the Playwright browser workflow). The 2026-09-20 receipt still qualifies 16.3.5 only.daguin this repository'smanifests/stack.jsonat 2.16.6. That pin is bound to VelaNext and other host evidence, and it lacks dagu v2.17.2's fix for secrets stored in plain text in step outputs (fix: mask secrets in stored step outputs dagucloud/dagu#2861). VelaNext is managed from its own sessions, so its owner re-qualifies it; this PR does not change it.🤖 Generated with Claude Code