Skip to content

chore: ignore GHSA-jmr9-qjv8-65gv in osv-scanner - #9490

Merged
veetragjain merged 1 commit into
masterfrom
veetragjain/cshld-1470-osv-scanner-failing-on-ghsa-jmr9-qjv8-65gv-extract-zip-add
Aug 13, 2026
Merged

chore: ignore GHSA-jmr9-qjv8-65gv in osv-scanner#9490
veetragjain merged 1 commit into
masterfrom
veetragjain/cshld-1470-osv-scanner-failing-on-ghsa-jmr9-qjv8-65gv-extract-zip-add

Conversation

@veetragjain

Copy link
Copy Markdown
Contributor

extract-zip 2.0.1 does not validate symlink targets during extraction (CVE-2026-56876, HIGH). It reaches us transitively through cypress and @puppeteer/browsers, both devDependencies, and both only ever extract vendor-published Cypress/Chromium binaries — never untrusted archives.

No upstream fix exists: the advisory reports last_affected 2.0.1 with no fixed event, and 2.0.1 is the latest published release. Excluded with a 2026-11-13 re-evaluation date.

Ticket: CSHLD-1470

@linear-code

linear-code Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

CSHLD-1470

@veetragjain
veetragjain marked this pull request as ready for review August 13, 2026 08:59
@veetragjain
veetragjain requested review from a team as code owners August 13, 2026 08:59
@veetragjain
veetragjain merged commit dec692f into master Aug 13, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants