OSV ignore ledger: @anthropic-ai/sdk 0.81.0 under the pinned claude-agent-sdk — drop on the next harness bump (by 2026-11-30)
- Dominant language
- TypeScript
- Stars
- 133k
- Forks
- 19.9k
- Avg merge
- 18h 46m
- Merged PRs (30d)
- 26
Description
The v1.78.0.0 wave's OSV pass suppresses GHSA-p7fg-763f-g4gf (@anthropic-ai/sdk 0.81.0, 4.8 MEDIUM) with `ignoreUntil = 2026-11-30` in `.osv-scanner.toml`.
Why not fixed in the wave: the vulnerable node is nested under @anthropic-ai/claude-agent-sdk@0.2.117, which is deliberately exact-pinned for eval-harness stability (the v1.77 wave pinned the whole harness after repeated CLI-drift breakage) and declares ^0.81.0 — a 0.x caret, so the 0.91.1 fix is out of range and forcing it via overrides would violate the harness pin for a MEDIUM.
Upgrade trigger: the next deliberate claude-agent-sdk bump. When that pin moves, drop this ignore in the same commit. If the ignoreUntil expiry (2026-11-30) fires first, the weekly OSV lane goes red and this decision must be re-justified or re-dated here.
Contributor guide
Research direction
Start with .osv-scanner.toml and verify the GHSA-p7fg-763f-g4gf ignore and expiry. When the exact claude-agent-sdk pin is deliberately bumped, remove that ignore in the same commit and run the weekly OSV lane to confirm it remains green.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Refactor
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 72/100