Skip to content

Bump the application-delivery lock to Next.js 16.3.6 for GHSA-vcvr-r3jv-pc5j - #252

Merged
seathatflowsinourveins merged 2 commits into
mainfrom
claude/nextjs-16.3.6-20260925
Sep 25, 2026
Merged

seathatflowsinourveins merged 2 commits into
mainfrom
claude/nextjs-16.3.6-20260925

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Why

Next.js v16.3.6 fixes GHSA-vcvr-r3jv-pc5j (CVE-2026-94545). The advisory is critical: remote code execution in next/og ImageResponse, affecting >= 16.2.0 < 16.3.6. The release was published 2026-09-22T17:15:10Z at tag commit a758ffcf501f6f1ddb03175bd1033508424c261e and is not a prerelease. Because this is a security fix, it takes the urgent-fix exception instead of waiting out the 7-day cooldown.

Exposure. rg -n --hidden "next/og|ImageResponse|@vercel/og" over the whole repository returns no matches, and the same search in agent-ecosystem also finds nothing. The fixture's app/ serves a static icon.svg, so it never reached the vulnerable path. The bump takes the vulnerable package out of the lock.

What changed

  • blueprints/convergence-practice/application-delivery/package.json: next 16.3.5 -> 16.3.6.

  • pnpm-lock.yaml: regenerated with the fixture's own pnpm 12.4.2 (pnpm install --lockfile-only --ignore-scripts).

    • Only next, @next/env and the eight @next/swc-* entries change.
    • All ten integrity values equal registry.npmjs.org dist.integrity for 16.3.6.
    • next@16.3.6 declares the same dependency and peer ranges as 16.3.5.
    • npm publishes a SLSA v1 provenance attestation for it.
  • history/recipe-revisions.json: keeps the 16.3.5 package.json and pnpm-lock.yaml under history/ with their receipt hashes, following the existing Makefile/serve.py pattern. It records the source review and the checks below. The README gets a short note.

  • manifests/stack.json, the saturation-audit.json row and the catalogs/landscape/upstream-snapshot.json record move to 16.3.6 / a758ffc.

    • The snapshot record comes from a fresh run of the same four gh api endpoints.
    • The manifests/evidence.json hashes are updated.
  • experiment.json (a recorded convergence experiment) bound pnpm-lock.yaml by path and hash, so validate_convergence --all-recorded failed once the lock moved. Its frozen_inputs.sources[4] now names the byte-identical retained history/pnpm-lock.0472177.yaml; the frozen hash and every other byte are unchanged. The original record is kept as history/experiment.json.0472177. Without a .json suffix it stays out of record discovery, like Makefile.cabbe2c. A new portability test checks that the path is the only change.

sources.json, receipt.json and freeze.json are unchanged. With experiment.json, they still describe the 2026-09-20 acceptance of 16.3.5.

Evidence (Mac arm64, Node 24.21.0, pnpm 12.4.2)

  • pnpm install --frozen-lockfile --ignore-scripts: passed.
  • pnpm peers check: no issues.
  • pnpm typecheck: passed.
  • NEXT_TELEMETRY_DISABLED=1 pnpm build: passed; 3 static routes.
  • test_portability.py: 6 tests OK. It now also verifies the two new retained-file mappings and the relocated frozen input.
  • These all pass: validate.py, host_receipts.py validate, validate_catalogs.py, validate_foundation.py, landscape.py, build_ecosystem.py --check, component_matrix.py --check, new_host_grand_list.py --check, build_verdicts.py --check, gap_crosswalk.py build --check, gap_wave_ledger.py --check, validate_convergence.py --all-recorded, audit_reports.py --check and evidence_manifest.py --check.
  • python3 -m unittest: 5072 tests, 2 failures. Both also fail on unmodified main on this Mac, and both are local-environment issues:

Gaps

  • The full make verify was not rerun at 16.3.6 (PostgreSQL build, API tests and the Playwright browser workflow). The 2026-09-20 receipt still qualifies 16.3.5 only.
  • This PR leaves dagu in this repository's manifests/stack.json at 2.16.6. That pin is bound to VelaNext and other host evidence, and it lacks dagu v2.17.2's fix for secrets stored in plain text in step outputs (fix: mask secrets in stored step outputs dagucloud/dagu#2861). VelaNext is managed from its own sessions, so its owner re-qualifies it; this PR does not change it.

🤖 Generated with Claude Code

…jv-pc5j

Next.js 16.3.6 (tag commit a758ffc, published 2026-09-22, not a
prerelease) fixes GHSA-vcvr-r3jv-pc5j / CVE-2026-94545, a critical
remote code execution in next/og ImageResponse that affects
>= 16.2.0 < 16.3.6. Because it is a security fix, it takes the urgent-fix
exception instead of waiting out the 7-day cooldown.

rg over the whole repository finds no next/og, ImageResponse or
@vercel/og use, and app/ serves a static icon.svg. The fixture never
reached the vulnerable path; the bump takes the vulnerable package out
of the lock.

- package.json: next 16.3.5 -> 16.3.6. pnpm-lock.yaml was regenerated
  with the fixture's own pnpm 12.4.2. Only next, @next/env and the eight
  @next/swc-* entries change, and all ten integrities equal
  registry.npmjs.org dist.integrity for 16.3.6.
- history/recipe-revisions.json keeps the 16.3.5 files under history/
  with their receipt hashes, following the Makefile/serve.py pattern, and
  records the source review and the checks that passed: frozen install,
  pnpm peers check, pnpm typecheck and the production build. The
  PostgreSQL, API and browser stages were not rerun, so the 2026-09-20
  receipt still qualifies 16.3.5 only.
- manifests/stack.json, the saturation-audit row and the landscape
  upstream-snapshot record move to 16.3.6 / a758ffc. The snapshot
  record comes from a fresh run of the same four gh api endpoints.
  The evidence hashes are updated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@socket-security

socket-security Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​next@​16.3.661100909970

View full report

…lock

experiment.json's frozen_inputs bind pnpm-lock.yaml by path and
sha256. validate_convergence --all-recorded failed once the lock moved
to 16.3.6. The record's pnpm-lock input now names the byte-identical
retained copy history/pnpm-lock.0472177.yaml. The frozen hash and every
other byte of the record are unchanged, and the experiment still
qualifies only the 16.3.5 lock it ran with.

The original experiment.json is kept as history/experiment.json.0472177.
A name without a .json suffix keeps it out of convergence record
discovery, like Makefile.cabbe2c. recipe-revisions.json records the
relocation, and a new portability test checks it: the retained bytes,
the current hash, the path as the only change, and the target lock's
hash.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins merged commit c96c255 into main Sep 25, 2026
24 of 27 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the claude/nextjs-16.3.6-20260925 branch September 25, 2026 15:02
seathatflowsinourveins added a commit that referenced this pull request Oct 6, 2026
)

### Scope

Fix the newly reviewed advisories that blocked every required OSV check: target only fsspec 2026.6.0/multidict 6.9.1 in the OpenHands runtime lock, Mako 1.4.2 in the application Python lock, and source-map-js 1.2.2 in its pnpm lock. Preserve all other package pins and the original captured artifact bytes.

The command center selected a dated source-backed exception for the frozen macOS input in its isolated config, and exclusion of both retired Lumibot lockchecks after the owner's confirmation. Each lock has native before/after evidence and its supported installation/qualification checks. No workflow or branch-protection setting changes.

- Base: `ecfa112764c664d35377dd66b8cfcb67e5a94d60` (fetch confirmed current main).
- Lane: `lane:foundation`.
- Owned scope: three production locks, SDK pins/research/evidence, qualification and ruling receipts, bounded OSV configuration/inventory, existing binding/no-use guards and closure record. Evidence registry committed last.

## SOTA sources

- [fsspec advisory GHSA-27vj-qcqg-25rc](GHSA-27vj-qcqg-25rc), [official 2026.6.0 release metadata](https://pypi.org/pypi/fsspec/2026.6.0/json), [maintainer tag](https://github.com/fsspec/filesystem_spec/tree/2026.6.0).
- [multidict advisory GHSA-54p9-h82j-f925](GHSA-54p9-h82j-f925), [official 6.9.1 release](https://github.com/aio-libs/multidict/releases/tag/v6.9.1), [PyPI metadata](https://pypi.org/pypi/multidict/6.9.1/json).
- [Mako advisory GHSA-5639-2j2p-m4mx](GHSA-5639-2j2p-m4mx), [maintainer release](https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2), [official metadata](https://pypi.org/pypi/Mako/1.4.2/json).
- [source-map-js advisory GHSA-68fv-2mgg-jv7q](GHSA-68fv-2mgg-jv7q), [published 1.2.2 metadata](https://registry.npmjs.org/source-map-js/1.2.2), [maintainer fix PR79](7rulnik/source-map-js#79).
- Dependent ranges: [Hugging Face Hub0.35.3](https://pypi.org/pypi/huggingface-hub/0.35.3/json), [aiohttp3.14.3](https://pypi.org/pypi/aiohttp/3.14.3/json), [yarl1.22.0](https://pypi.org/pypi/yarl/1.22.0/json), [Alembic1.20.0](https://pypi.org/pypi/alembic/1.20.0/json), [PostCSS8.5.23](https://registry.npmjs.org/postcss/8.5.23). Complete declared-parent checks include optional/null metadata handling; limitations remain explicit in receipts.
- [#562 at74cc5468](#562): original builder/relock/hash/install/scan/guard pattern. Installed [uv0.12.22](https://github.com/astral-sh/uv/releases/tag/0.12.22) reproduces the accepted baseline byte for byte; #562's0.12.17 remains historical.
- [#587 at798ac445](#587), [#252 atc96c2555](#252): bounded frontend qualification. [pnpm12.4.2 update parser](https://github.com/pnpm/pnpm/blob/9502f3c457717dae3a4ddbf4315a8c4aee16fdb4/pnpm/crates/cli/src/cli_args/update.rs) and [supported update docs](https://pnpm.io/cli/update): selective bare-name transitive update, no-save/lockfile-only; obsolete explicit-version/Infinity forms avoided.
- Frozen config precedent [8fc8611](8fc8611) and the maintained closure at `docs/decisions/2026-09-22-github-automation-closure.md`. Indexed source offsets/reconstruction inspected at [source-map-js1.2.1](https://github.com/7rulnik/source-map-js/blob/428d49f6b1e1614f082b7706fa879a3d9c64f728/lib/source-map-consumer.js#L944). Dedicated input/digest/expiry guards retained.
- Trial [#336 at20b52a5b](#336), existing captured XNYS exclusion precedent, and command-center ruling `task-ns2604-coop-20261006T003954Z`. The verified owner confirmation is a **report** row: `report-native-agent-stack-5f-20261006T0045Z-osv`, from `native-agent-stack-5f`, at `2026-10-06T00:41:23Z`, replying to `task-native-agent-stack-5f-20261006T004011Z`. Sanitized evidence: `evidence/receipts/osv-captured-lumibot-lockchecks-20261005.json`. No trial replay or new host-process census is claimed.

### Evidence-class table

| Claim | Class | Actual result |
| --- | --- | --- |
| Published dependent ranges permit the fixes | source_review | Complete pinned metadata review; no caps/errors; exact parents linked above |
| Targeted locks preserve other pins | local_integration | SDK byte-identical control; only two package blocks move. Mako only package block, native lock revision3→5 recorded. pnpm manager/importers unchanged; only source-map-js move |
| Release identity and supported artifact hashes match | local_integration | Native hash checks0: fsspec2, multidict14, Mako2; universal wheels/sdist included |
| Supported isolated/native qualification succeeds | local_integration | SDK178-package check/imports0; backend28-package check/import/render0; frontend frozen install/peers/typecheck/build0 |
| Both required scan partitions pass locally | local_integration | Before:60ordinary/1frozen,5+1 unignored findings. After:58ordinary/1frozen, actual native exits0/0, zero unignored findings |
| Binding/coverage/no-use guards remain effective | local_integration / synthetic |70 touched tests0; clean control0; all deliberate negative controls1 as expected |
| Registry integrity | local_integration | validate.py0;69components/4profiles/212receipts/10309hashes; integrity only |
| Hosted, image, provider and full API/browser acceptance | unknown | No claim; command-center exact-head cross-family read remains pending |

### Local commands run

All heavy phases used nice19; scratch/cache and installs were isolated. Exact supported commands and sanitized actual returned output/hashes are retained in the three relock prefixes and linked receipts.

```
#562-pattern paired native uv control/targeted lock/check/export:0
native release hash checks:0
hashed SDK install / uv pip check / exact imports:0
targeted Mako lock/check; frozen/no-build sync; pip check; imports/render:0
pnpm12.4.2 update source-map-js --no-save --lockfile-only --ignore-scripts:0
pnpm install --frozen-lockfile --ignore-scripts; peers check; typecheck; build:0
python -m unittest tests.test_openhands_lock_binding tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use
70 tests; latest final data-pin run6.936s; exit0
OSV2.6.0 ordinary scan:0; frozen scan:0
python3 scripts/validate.py:0,10309hashes
component_matrix --write:0,32rows/zero flips
new_host_grand_list --write:0,32layers/66winners
git diff --check and git diff --cached --check:0
```

### Failed conditions

The initial root-added UV_NO_CONFIG1 discarded the resolver's Linux workspace settings; the next copied formatter inserted two plus signs. Native lock/check/export succeeded in both, while the relock byte-comparison script failed. Neither candidate was adopted; both are disclosed separately. Test preflight rejected inside-checkout TMPDIR before execution; existing external lane cache was used. Intermediate stale receipt/unreviewed metadata-line guards failed before being corrected. Publication caught one private interpreter path in a negative-control trace; it was sanitized. Terminal progress whitespace was normalized and its capture hash rebound. No failure is promoted to a passing upstream test.

### Decision record

`docs/decisions/2026-09-22-github-automation-closure.md`, "Four production relocks and preserved receipt inputs (2026-10-06)"; SDK research section and qualification/ruling receipts record alternatives, source/replay limits and overturn conditions. The macOS exception expires2026-12-24; its `.frozen` rename is a separate follow-up. Future use of captured trial dependencies requires a separately maintained/scanned qualification environment.

### Host evidence

No evidence/hosts or platform-status flip. The native runtime imports/builds are local integration; source reviews, synthetic controls and hosted acceptance remain separate. Exact-head command-center review is requested.

### Checklist

- [x] No workflow/action permission or branch-protection change.
- [x] No credential value or authentication store read/printed/copied; no new required secret.
- [x] No paid hosting, provider/model runtime call, deployment or restart.
- [x] Peer-owned worktrees preserved; three captured locks remain byte-identical.
- [x] Registry committed last; one lane:foundation label.
- [x] Ordinary AND frozen native scans and touched tests passed before ready.
- [ ] Command-center exact-head cross-family read and 5f landing; lane never merges.

## Dated input-binding repair (2026-10-06)

The command-center exact-head read of67c6594d2 found two omitted downstream gates: both convergence records still resolved their original UV digest through the newly relocked live file, and the recipe ledger's PNPM current digest was stale. This amendment preserves trial evidence instead of attributing new dependencies to the original runs.

- Retain ecfa112 UV/PNPM bytes and the two pre-amendment experiment snapshots byte-for-byte.
- Change only each canonical record's UV input path; keep frozen digests, commands, observations, outputs and usage. Both records remain declared.
- Append dated recipe supersession/current mappings and ordered path relocations; protect original/prior/superseded bytes and all non-path record bytes with the portability assertions.
- Source: [#252 path-only relocation](https://github.com/seathatflowsinourveins/native-agent-stack/blob/c96c2555c2d84683d9e519623354c814aeb6a584/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L121) and [#587 supersession](https://github.com/seathatflowsinourveins/native-agent-stack/blob/798ac445307e2cd8eba6e74d7722ac0e16da02c7/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L99).
- Dated decision/source receipt: `docs/decisions/2026-10-06-application-input-binding-amendment.md`, `evidence/receipts/pr765-bindings-amendment-20261006.json`.

Before repair, all-recorded convergence exited1 (2invalid/32) and native-maintenance exited1 (29cases/one PNPM mismatch). Repaired focused checks: native-maintenance29passed; convergence/OSVcoverage/frozenMAC102passed. After main-registry refresh and full own-file re-registration, local validate0/10315hashes and all-recorded convergence0/32valid. Full local suite ran under A22's specific copied-fixture `install.sh --list` exception and exited1:10,343tests/2217.568s,18failures/18errors/905skips. Installer apply paths remain banned. Raw output is retained privately; known systemd parser (#767), missing calendar/mutation imports, PATH fixtures, token-canary fixtures and installed Windows Terminal type drift are recorded separately, never presented as a pass.

Old reviewed head's hosted baseline was6/7 required contexts: validate failed, six others passed. Required acceptance is measured at the new pushed head; no workflow rerun loop or old local check is promoted into that acceptance. No production pin, recorded trial output, raw receipt, frozen macOS lock, captured trading lock or scanner exclusion changed in this repair.
seathatflowsinourveins added a commit that referenced this pull request Oct 6, 2026
### Scope

Patch the live application recipe's sharp 0.35.4 dependency to the first fixed release 0.35.5 for GHSA-wq5f-xc86-pv6w. Its required Sharp/@img family moves with it; the captured macOS lock stays byte-identical under one file-scoped exception expiring 2026-12-24.

- Base commit: `0d5e6506434fab598dee861c749a22e628beb75a`.
- Lane: `lane:foundation`.
- Owned paths: live application pnpm lock, retained prior lock and recipe history, bounded qualification outputs, dedicated frozen-macOS exception, its coverage test, dated decision, qualification receipt and evidence registry.
- `.github/osv-scanner.toml` and `.github/osv-scanner-lockfiles.json` are byte-identical to the base. The frozen variant retains SHA-256 `f1c707b8295e85bd396e49b990de92dc82bc0d58eca1e4e4bef31262d9898cd2`.

## SOTA sources

- [Sharp maintainer advisory GHSA-wq5f-xc86-pv6w](GHSA-wq5f-xc86-pv6w), published 2026-10-06T13:43:57Z: affected `<0.35.5`, first patched `0.35.5`, librsvg CVE-2026-96889.
- [Sharp v0.35.5 release](https://github.com/lovell/sharp/releases/tag/v0.35.5), published 2026-09-27T13:44:22Z, `lovell/sharp@51a990faa26ade5586a4934ac9673c98d8893326`; [sharp-libvips v1.3.4](https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4) supplies librsvg 2.63.2.
- [pnpm supported targeted update](https://pnpm.io/cli/update) and [frozen-lockfile installation](https://pnpm.io/cli/install), read 2026-10-06; installed pinned pnpm 12.4.2 help/error rejects a versioned selector on an indirect dependency. Published latest and the resulting resolved version were independently checked as exactly 0.35.5; no override or package.json edit was needed.
- [Next 16.3.8 published metadata](https://registry.npmjs.org/next/16.3.8): its `optionalDependencies.sharp` range `^0.35.4` permits 0.35.5. This is the lock's only direct dependent on sharp. All 27 replacement resolution integrity values match published npm metadata; 67 unrelated package entries, importers and the pnpm manager document remain unchanged.
- [Sharp source at the prior pin](https://github.com/lovell/sharp/blob/7f1a0a22cc285fe180766f4935d50b55af6e8432/src/common.cc#L323), `src/common.cc:323,506,596`, and `src/pipeline.cc:48`: SVG file/buffer input can reach librsvg. Exception justification rests on the retained variant having no supported installer/build/server/replay consumer found in scoped source review, with removal before any manual replay or new consuming route; the macOS label is not itself a reachability exemption.
- Repository conventions: `native-agent-stack@0d5e650:blueprints/convergence-practice/application-delivery/Makefile:3-5,27-32`, `README.md:170-180`; [#765](#765), [#587](#587) and [#252](#252) retain prior bytes/qualifications and append supersessions. Original full-stack receipts and canonical experiment records remain untouched.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| First patched release, dependent range and SVG reachability | source_review | Maintainer advisory/release, pinned source and published npm metadata above |
| Exact frozen install, peers, typecheck, production build, loaded sharp/librsvg versions | local_integration | `relock-2026-10-06-sharp.*.txt`; `evidence/receipts/sharp-0355-qualification-20261006.json` |
| Frozen byte identity, retained old live lock and bounded family-only changes | local_integration | Hash/source comparisons and recipe revision ledger; 27 replacements / 67 unrelated unchanged |
| Repository integrity and declared-record consistency | local_integration | Validator, 32 convergence records and 96 touched tests pass; these do not establish upstream or live application acceptance |
| Advisory present for sharp 0.35.4 and absent for 0.35.5 | source_review | Supported OSV version-query API; this is not a native scanner or full-inventory scan |
| Complete application/API/browser qualification | local_integration, failed | `make verify` exits 2 on 12 dedicated-PostgreSQL setup errors; browser attempt exits 1 on occupied configured port 18080, with no browser case executed |
| Required hosted OSV and other CI checks | pending | Must be observed at this PR's head; no local scanner executable was found in the inspected locations |

### Local commands run

Frontend commands below ran in the live application directory, using the recipe's pinned pnpm 12.4.2 through Corepack, task-private cache/store/state/temp paths and a public-registry-only npmrc; heavy commands ran one at a time at nice 19. `relock-2026-10-06-sharp.sh.txt` records the supported replay pattern. Worktree/state path prefixes are sanitized in public outputs.

```text
corepack pnpm update sharp --no-save --lockfile-only --ignore-scripts
exit 0; exact resolved sharp 0.35.5 checked
corepack pnpm install --frozen-lockfile --ignore-scripts
exit 0
corepack pnpm peers check
exit 0
corepack pnpm typecheck
exit 0
corepack pnpm build
exit 0
node -e 'const r=require("module").createRequire(require.resolve("next/package.json"));const s=r("sharp");console.log(JSON.stringify({sharp:s.versions.sharp,vips:s.versions.vips,rsvg:s.versions.rsvg}));if(s.versions.sharp!=="0.35.5"||s.versions.rsvg!=="2.63.2")process.exit(1)'
exit 0; sharp 0.35.5, vips 8.18.7, rsvg 2.63.2
nice -n 19 python3 scripts/validate.py
exit 0; 69 components, 4 profiles, 214 receipts, 10,345 hashed files
nice -n 19 python3 scripts/validate_convergence.py --all-recorded --json
exit 0; all 32 records valid
nice -n 19 python3 -m unittest tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use tests.test_native_maintenance
exit 0; 96 tests, repeated after the new files were staged
git diff --check
exit 0
git diff --cached --check
exit 0 after explicit output whitespace sanitization
```

### Failed attempts and acceptance limits

- `pnpm update sharp@0.35.5 --no-save --lockfile-only --ignore-scripts` exits 1 with `ERR_PNPM_UPDATE_VERSION_ON_INDIRECT_DEP`, before mutation. The supported unversioned indirect update resolves exactly the independently verified first patch; no override is added.
- A single-document PyYAML read exits 1 because pnpm 12 stores two YAML documents; upstream `safe_load_all` corrects the comparison.
- First `make verify` exits 2 because pnpm is not on PATH. Supported Corepack enable creates only task-private shims. The second unchanged run passes schema/type/build checks on supported Python 3.13.16, then exits 2 on 12 PostgreSQL connection-timeout setup errors. The full actual failed log is retained privately and its decisive counts/cause in the public receipt. No PostgreSQL build, container/image pull or global installer was introduced.
- Separate unchanged `pnpm test:e2e` exits 1 because port 18080 is occupied and Playwright's recipe refuses reuse. No other owner's service was stopped and no test was relaxed. Full-stack acceptance remains unfinished.
- Initial staged diff checking found three trailing build-progress spaces. They were trimmed with that sanitization explicitly recorded, their hashes re-registered and the check repeated. Actual private output remains retained.
- Native full-inventory OSV execution and unchanged upstream tests are unclaimed. The database's zero finding for the fixed version does not replace the required hosted scanner verdict.

### Decision record

`docs/decisions/2026-10-06-sharp-live-relock-frozen-variant.md` records the targeted patch, rejected broad-ignore/historical-rewrite alternatives and evidence boundaries. Remove or re-review the frozen exception before replay, a new consumer, changed bytes or 2026-12-24. Registry is committed last. Independent bounded source/scope critic accepted this separation; co-op GPT micro-check and command-center exact-head ACK are requested. PR stays draft for that read; 5f owns landing.

### Host evidence

No `evidence/hosts/` change or platform-status claim.

- [ ] Host-receipt validation: not applicable.
- [ ] Command-center exact-head review requested; no platform status flip.

### Checklist

- [x] No workflow/action change; existing pinned actions and permissions stay untouched.
- [x] No secrets are printed, logged or committed; no new required secret.
- [x] No paid hosting or billing surface.
- [x] Peer-owned paths, services and worktrees preserved.
- [x] Frozen evidence remains byte-identical; registry last; no merge or settings change.

### Review follow-up — 2026-10-06

The co-op relays CC item `task-ns2604-coop-20261006T170124Z`, ruling 2: accept the disclosed browser gap for this urgent security landing conditional on a fresh frozen install/frontend build and restoration of the unrelated Mako JSON escape spelling. Both fresh frontend commands passed. `make postgres-init` exits 2 (inner 127) because the recipe's `.runtime/postgresql/18.6/bin/initdb` is missing. The recipe's `postgres-install` source-build target was not run under the upstream-never-rebuild and park rules. Playwright fixes both service and base URLs to port 18080, held by the local alert service; the service is untouched. No new browser cases ran.

Source: `native-agent-stack@4f32d59:blueprints/convergence-practice/application-delivery/Makefile:3-5,27-32,34-58` and `playwright.config.ts:8-16`; original Mako row at base `0d5e6506`. Full sanitized argv, return codes, actual outputs and classes are in `evidence/receipts/sharp-review-followup-20261006.json` and `relock-2026-10-06-sharp.review-*.txt`. Actual returned output remains privately durable; public progress whitespace/EOF normalization is explicit. The original qualification receipt and production/frozen locks stay byte-identical to the reviewed head.

```text
pnpm 12.4.2 install --frozen-lockfile (task-private cache/store/state/public-registry config)
exit 0; lock current, resolution skipped, 26ms
NEXT_TELEMETRY_DISABLED=1 pnpm build
exit 0; Next 16.3.8 production build
make postgres-init
exit 2; missing .runtime/postgresql/18.6/bin/initdb, inner 127
nice -n 19 python3 -m unittest tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use tests.test_native_maintenance
exit 0; 96 tests, 8.999s
nice -n 19 python3 scripts/validate.py
exit 0; 69 components, 4 profiles, 214 receipts, 10,349 hashed files
```

Both original literal Mako `\u2192` spellings now exactly match the base row; parsed values are unchanged. Dated unfinished follow-up after the tools window: qualify the dedicated test DB through an upstream-supported release path and run the unchanged browser recipe in an isolated network namespace if no supported port override exists. Frontend build is not a browser/image-response or exploit test. Independent bounded source critic accepts the repair and separation. New-head co-op micro-check/CC ACK and hosted checks still required; registry is committed last. No broad ignore, alert-service takeover, source build, host configuration or merge.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant