Skip to content

fix(deps): resolve joi 18.2.9 for the wait-on dev tool (GHSA-6h2x-m376-mqjq) - #909

Merged
qnbs merged 4 commits into
mainfrom
fix/joi-ghsa-6h2x
Sep 29, 2026
Merged

qnbs merged 4 commits into
mainfrom
fix/joi-ghsa-6h2x

Conversation

@qnbs

@qnbs qnbs commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

User description

User description

Part of #872.

Why

The tag-triggered CI/CD run 36618279795 for v1.29.0 failed its enforced Security Audit OSV scan:

  • GHSA-6h2x-m376-mqjq / CVE-2026-92599 (high): joi 18.2.5, fixed in 18.2.6.
  • Path: root devDependency wait-on 9.1.0 → joi 18.2.5. A second copy, 18.2.8 via wait-on 7.2.0, was not affected.

Reachability (evidence, not a waiver)

wait-on is only a CI/E2E tool that waits for a local server (ci.yml lines 948 and 1075, storybook-debug.yml). The three shipped v1.29.0 CycloneDX SBOMs, generated from the production dependency graph of the exact candidate, contain 0 joi and 0 wait-on components. react is present, which confirms the check itself works. So there is no shipped runtime exposure.

The gate is still deterministic and enforced, so the fix does not add an ignore entry or change the scanner config.

Change

  • Lockfile: a refresh inside the existing range (pnpm update joi --lockfile-only). Both joi copies now resolve to 18.2.9, which has no OSV record.
  • Override floor (root cause): the workspace override joi: ">=18.2.5 <19" still admitted the affected 18.2.5. It is raised to ">=18.2.6 <19", so a later re-resolution cannot fall back to an affected version.
  • AUDIT.md: the accepted-risk note and the Known Overrides row now match the real override and resolutions. They previously showed a stale ^18.2.1, joi 18.2.1 and wait-on 9.0.10. This was raised by CodeRabbit as an outside-diff comment.
  • Unchanged: package.json and osv-scanner.toml. There is no ignore entry.

Release disposition

The v1.29.0 tag (e0739537 on cf72dc6d) is kept and not moved.

  • No GitHub/desktop release was published. The Tauri release run 36618279797 was cancelled before its GitHub Release job.
  • GHCR container tags were already published. Before the cancellation, the tag-triggered Docker run 36618279810 had pushed ghcr.io/qnbs/worldscript-studio:1.29.0, :1.29 and :latest to digest sha256:1f463bc6ba1e2544b9d8c2191814c3eff50c9add81cd81d3d3927be736b3fe2d, with OCI revision cf72dc6d.
    • That image's runtime stage is nginx plus the static dist/ only (Dockerfile lines 22–28). joi exists only in the discarded builder stage.
    • These tags must be reconciled by the successor release: :1.29 and :latest will move to the v1.29.1 image, and :1.29.0 stays as the record of the unpublished tag.

Under the immutable-tag policy (the v1.28.5 → v1.28.6 precedent), the release continues as v1.29.1 after this fix and its resulting-main epoch.

Summary by Sourcery

Eliminate the vulnerable development-only joi resolution while preserving enforced security scanning without adding an ignore.

Bug Fixes:

  • Resolve the vulnerable transitive joi dependency used by CI and development tooling by updating both dependency paths to joi 18.2.9.

Enhancements:

  • Raise the workspace joi override floor to 18.2.6 to prevent reintroduction of the affected version.

Documentation:

  • Update the changelog and audit records with the fixed joi version, advisory information, and current dependency mappings.

CodeAnt-AI Description

Update the CI dependency to a security-fixed Joi release

What Changed

  • CI and test tooling now resolves joi to 18.2.9 instead of affected older versions.
  • The minimum allowed Joi version is raised to 18.2.6, preventing future installs of the vulnerable release.
  • Security audit records and the changelog now describe both affected wait-on dependency paths and the corrected versions.

Impact

✅ OSV security scans pass for the wait-on dependency
✅ Fewer vulnerable development-tool installations
✅ Clearer dependency security records

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

…6-mqjq)

The tag-triggered CI/CD run for v1.29.0 failed its enforced OSV scan on
joi 18.2.5 (CVE-2026-92599, high, fixed in 18.2.6), reached only through
the root devDependency wait-on 9.1.0. Lockfile-only refresh inside the
existing ^18.2.3 range: both joi copies now resolve 18.2.9. No manifest,
override or scanner-config change.
@codeant-ai

codeant-ai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 02bec27 Sep 29, 2026 · 20:44 20:46
✅ Reviewed your PR 1a1713e Sep 29, 2026 · 19:59 20:01
✅ Reviewed your PR 8f05317 Sep 29, 2026 · 19:34 19:37

@sourcery-ai

sourcery-ai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This lockfile-only dependency refresh resolves both Joi copies to 18.2.9, removing the reported OSV vulnerability from the CI/E2E wait-on dependency graph without changing package manifests, scanner configuration, or adding an ignore; reviewers should also confirm the immutable-tag and v1.29.1 release disposition.

File-Level Changes

Change Details Files
Refresh the lockfile to eliminate the vulnerable Joi resolution while preserving dependency manifests and scanner configuration.
  • Update both transitive Joi copies to 18.2.9 within the existing ^18.2.3 range.
  • Retain the current wait-on dependency structure without adding overrides or audit exceptions.
  • Limit the implementation to pnpm-lock.yaml changes.
pnpm-lock.yaml
Preserve the release and security-validation strategy while scheduling a new patch release.
  • Keep the existing v1.29.0 tag immutable and do not publish its cancelled release.
  • Use v1.29.1 for the corrected release after the fix reaches main.
  • Verify the enforced OSV audit passes without relying on the absence of shipped runtime reachability.

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Sep 29, 2026 8:24pm UTC

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 11 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 92 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: acbfeaad-4909-4ed1-bd5a-bcf3cfc8c453

📥 Commits

Reviewing files that changed from the base of the PR and between 328f0aa and 02bec27.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (3)
  • AUDIT.md
  • CHANGELOG.md
  • pnpm-workspace.yaml
📝 Walkthrough

Walkthrough

The changelog records the development dependency update from joi 18.2.5 to 18.2.9, the OSV scan failure, and that shipped desktop and web builds do not include joi or wait-on.

Changes

Dependency update record

Layer / File(s) Summary
Record the dependency update
CHANGELOG.md
The changelog records the joi version update, the OSV scan failure on the v1.29.0 tag, and build inclusion details. It also states that only the lockfile changed.

Priority: ⬇️ Low

Merge Risk: 🔵 Low · up to 328f0

Update the stale security-table entry before merging so reviewers see the current dependency versions. Automated scans use the lockfile, so the mismatch does not invalidate them.


Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:XS This PR changes 0-9 lines, ignoring generated files label Sep 29, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

sourcery-ai[bot]
sourcery-ai Bot previously approved these changes Sep 29, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

codescene-access[bot]

This comment was marked as outdated.

@codeant-ai

codeant-ai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 02bec27e
Scan Time: 2026-09-29 20:46:35 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found, 1 false positive secret suppressed
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED Rating S: No issues

View Full Results

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

Release-truth correction before merge:

The remediation itself is correct and the exact-head Security Audit already passes, including the OSV scan. However, the PR body's release-disposition sentence “so nothing was published” is too broad.

Before the Tauri cancellation, Docker run 36618279810 had already pushed:

  • ghcr.io/qnbs/worldscript-studio:1.29.0
  • ghcr.io/qnbs/worldscript-studio:1.29
  • ghcr.io/qnbs/worldscript-studio:latest

to digest:
sha256:1f463bc6ba1e2544b9d8c2191814c3eff50c9add81cd81d3d3927be736b3fe2d
with OCI revision cf72dc6db174ef8e7d37ccd3a47c564428fe656c.

The accurate statement is: no GitHub/Desktop Release was published; GHCR container tags were already published and must be reconciled by the v1.29.1 successor release.

Please fold this into the single correction wave with any other validated review findings. No scanner ignore/gate weakening is needed; the lockfile fix itself is already proven by the exact-head OSV gate.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to GitHub limitations.

⚠️ Outside diff range comments (1)

🟡 Minor · Update the Known Overrides Table to match the lockfile. · pnpm-lock.yaml:7610-7618

pnpm-lock.yaml:7610-7618
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Update the Known Overrides Table to match the lockfile.

AUDIT.md presents this table as current security guidance, but the row lists joi@18.2.1 and wait-on@9.0.10. The lockfile now resolves joi@18.2.9 for wait-on@7.2.0 and wait-on@9.1.0. This mismatch can mislead a human security review.

Suggested fix
-| joi (transitive via `wait-on` ← `@storybook/test-runner` → `jest-process-manager`) | ^18.2.1 | transitive hardening (dev-only) | `wait-on@7.2.0` originally pulled an older `joi`; lockfile pins `joi@18.2.1` for both `wait-on@7.2.0` and `wait-on@9.0.10`. Dev/test toolchain only, never shipped. |
+| joi (transitive via `wait-on` ← `@storybook/test-runner` → `jest-process-manager`) | ^18.2.1 | transitive hardening (dev-only) | `wait-on@7.2.0` originally pulled an older `joi`; the lockfile resolves `joi@18.2.9` for both `wait-on@7.2.0` and `wait-on@9.1.0`. Dev/test toolchain only, never shipped. |

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 327b3cdf-d0b4-4bcd-bcbc-ad7a5e4cf98f

📥 Commits

Reviewing files that changed from the base of the PR and between 8f05317 and 328f0aa.

📒 Files selected for processing (1)
  • CHANGELOG.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

Confirmed and folded in. The Docker run 36618279810 log shows manifests pushed for ghcr.io/qnbs/worldscript-studio:1.29.0, :1.29 and :latest @ sha256:1f463bc6…fe2d, before the Tauri cancel. I have corrected the PR body's release-disposition section and the #872 disposition comment. The statement now reads: no GitHub/desktop release was published; the GHCR tags were published and are reconciled by the v1.29.1 successor. I also checked that the image's runtime stage (Dockerfile lines 22–28) is nginx plus dist/ only, so joi is not in the published container either. There are no code changes, so the head stays 328f0aa8.

@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

#909)

The workspace override still admitted the affected joi 18.2.5 (>=18.2.5 <19); raise it to >=18.2.6 <19 so a later re-resolution cannot fall back to a GHSA-6h2x-m376-mqjq version. AUDIT.md's accepted-risk note and Known Overrides row named a stale ^18.2.1 range and old resolutions (joi 18.2.1, wait-on 9.0.10); both now match the override and lockfile.
@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai Outside-diff finding (AUDIT.md Known Overrides row): valid, fixed in 1a1713e1.

I fixed the root cause as well. The actual workspace override was joi: ">=18.2.5 <19", which still admitted the affected 18.2.5. It is now ">=18.2.6 <19", and the lockfile overrides: header matches.

Both AUDIT.md statements were stale:

  • the Known Overrides row, which you flagged;
  • the accepted-risk note at line 143, which also said ^18.2.1.

Both now name >=18.2.6 <19, joi@18.2.9 and wait-on@7.2.0/9.1.0. The CHANGELOG entry mentions the raised floor.

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

@codeant-ai codeant-ai Bot added size:S This PR changes 10-29 lines, ignoring generated files and removed size:XS This PR changes 0-9 lines, ignoring generated files labels Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail
printf 'HEAD: '; git rev-parse --short HEAD
printf '\nReferenced files:\n'
fd -i '^(AUDIT\.md|CHANGELOG\.md|package\.json|pnpm-lock\.yaml|package-lock\.json|yarn\.lock)$' .
printf '\nOverride and documentation references:\n'
rg -n -C 3 'Known Overrides|accepted.risk|joi@18\.2\.9|wait-on@|>=18\.2\.(5|6) <19|\^18\.2\.1|raised floor' --glob 'AUDIT.md' --glob 'CHANGELOG.md' --glob 'package.json' --glob 'pnpm-lock.yaml' --glob 'package-lock.json' --glob 'yarn.lock' . | head -220

Length of output: 15893


🏁 Script executed:

#!/bin/bash
set -euo pipefail
printf 'Workspace file:\n'; fd -i '^pnpm-workspace\.yaml$' .
printf '\nWorkspace override:\n'; rg -n -C 5 'joi:|overrides:' pnpm-workspace.yaml | head -90
printf '\nChangelog current entry:\n'; sed -n '1,65p' CHANGELOG.md
printf '\nAudit accepted-risk note:\n'; sed -n '140,145p' AUDIT.md
printf '\nAudit override row:\n'; sed -n '1855,1861p;1881,1886p' AUDIT.md
printf '\nLockfile header and dependency resolutions:\n'; sed -n '1,15p;15614,15633p' pnpm-lock.yaml

Length of output: 13589


@qnbs, I also verified the workspace override and changelog entry. The override, lockfile, and both AUDIT.md statements agree. The finding is addressed.


✏️ Learnings added
Learnt from: qnbs
URL: https://github.com/qnbs/WorldScript-Studio/pull/909

Timestamp: 2026-09-29T19:59:43.449Z
Learning: In WorldScript-Studio, the `joi` override in `pnpm-workspace.yaml` must exclude versions affected by GHSA-6h2x-m376-mqjq. The former floor `>=18.2.5 <19` admitted affected `joi18.2.5`; PR #909 raised it to `>=18.2.6 <19`. The `pnpm-lock.yaml` override must match, and both `wait-on7.2.0` and `wait-on9.1.0` resolve to `joi18.2.9`.

Note: Learnings are effective only in the context of similar code segments. To apply general coding guidelines, please configure review instructions. You can manage existing learnings in the app.

You are interacting with an AI system.

@codeant-ai

codeant-ai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

CodeAnt Nitpicks

1 code suggestion

1. The new row contradicts the earlier accepted-risk note, which still documents joi as ^18.2.1 instead of the current &gt;=18.2.6 &lt;19 override.

Comment mismatch · AUDIT.md:1884

…on paths (PR #909)

The accepted-risk note sits in the dated v1.24.0 section, so it returns to its original wording; the current joi state lives in the Known Overrides table, which now names both paths: the root devDependency wait-on@9.1.0 and wait-on@7.2.0 via jest-process-manager and @storybook/test-runner.
@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

CodeAnt nitpicks on 1a1713e1: both valid, fixed in 02bec27e.

  1. AUDIT.md:143 chronology. That note sits in the dated v1.24.0 section. It is restored verbatim to its origin/main wording (historical record). The current joi state lives only in the Known Overrides table.

  2. AUDIT.md Known Overrides path. The row now names both paths, checked against the lockfile:

    • root devDependency wait-on@9.1.0;
    • wait-on@7.2.0 ← jest-process-manager@0.4.0 ← @storybook/test-runner@0.24.5.

    The earlier arrow direction was also inverted, and that is corrected too.

@CodeAnt-AI review

@codeant-ai

codeant-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Question: codeant nitpicks on 1a1713e1: both valid, fixed in 02bec27e.

  1. audit.md:143 chronology. that note sits in the dated v1.24.0 section. it is restored verbatim to its origin/main wording (historical record). the current joi state lives only in the known overrides table.

  2. audit.md known overrides path. the row now names both paths, checked against the lockfile:

    • root devdependency wait-on@9.1.0;
    • wait-on@7.2.0 ← jest-process-manager@0.4.0 ← @storybook/test-runner@0.24.5.

    the earlier arrow direction was also inverted, and that is corrected too.

review

Answer:
Both CodeAnt nitpicks are valid and appear correctly addressed in 02bec27e:

  1. Chronology in AUDIT.md
    The note in the dated v1.24.0 section has been restored to the historical origin/main wording, avoiding retroactive changes to the audit record. The current joi remediation is documented in the Known Overrides table instead.

  2. Known Overrides dependency path
    The joi row now accurately identifies both dependency paths:

    • Root dev dependency: wait-on@9.1.0
    • Transitive path: @storybook/test-runner@0.24.5 → jest-process-manager@0.4.0 → wait-on@7.2.0

    The arrow direction has also been corrected to reflect the dependency flow. The lockfile confirms that both wait-on versions now resolve to joi@18.2.9, while the workspace override enforces the secure floor >=18.2.6 <19.

No further issues are apparent from these questions.

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No application code in the PR — skipped Code Health checks.

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author

CodeAnt nitpick on 02bec27e (AUDIT.md:143 vs 1884): deferred, with a recorded destination.

This contradicts the previous nitpick on 1a1713e1, which asked for line 143 (in the dated v1.24.0 section) not to carry v1.29-era content. Here is the resolution that satisfies both:

  • keep the historical wording;
  • append a neutral forward pointer ("range later raised; current value in the Known Overrides table").

That is a P3 doc-consistency edit with no effect on the fix. It goes into the v1.29.1 release-prep PR, which edits AUDIT.md anyway, so the full CI matrix is not restarted here. The authoritative current state (>=18.2.6 <19, joi@18.2.9, both paths) is already in the Known Overrides row, pnpm-workspace.yaml and the lockfile.

@qnbs
qnbs merged commit 71f4a4a into main Sep 29, 2026
43 checks passed
@qnbs
qnbs deleted the fix/joi-ghsa-6h2x branch September 29, 2026 20:58
qnbs added a commit that referenced this pull request Oct 10, 2026
#909)

The workspace override still admitted the affected joi 18.2.5 (>=18.2.5 <19); raise it to >=18.2.6 <19 so a later re-resolution cannot fall back to a GHSA-6h2x-m376-mqjq version. AUDIT.md's accepted-risk note and Known Overrides row named a stale ^18.2.1 range and old resolutions (joi 18.2.1, wait-on 9.0.10); both now match the override and lockfile.
qnbs added a commit that referenced this pull request Oct 10, 2026
…on paths (PR #909)

The accepted-risk note sits in the dated v1.24.0 section, so it returns to its original wording; the current joi state lives in the Known Overrides table, which now names both paths: the root devDependency wait-on@9.1.0 and wait-on@7.2.0 via jest-process-manager and @storybook/test-runner.
qnbs added a commit that referenced this pull request Oct 10, 2026
fix(deps): resolve joi 18.2.9 for the wait-on dev tool (GHSA-6h2x-m376-mqjq)
qnbs added a commit that referenced this pull request Oct 10, 2026
v1.29.1 succeeds the signed v1.29.0 tag, whose tag-triggered CI/CD failed the enforced OSV scan on the development-only joi 18.2.5 (fixed by #909); its desktop release was cancelled before publication and the tag stays immutable. Version 1.29.1 in all five sync authorities; CHANGELOG 1.29.1 section with a candidate marker and a never-published note on 1.29.0; README/AUDIT/TODO truth; v1.29.0 outcome recorded and docs/RELEASE-V1.29.1-EVIDENCE.md added.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant