garrytan / garrytan/gstack

OSV ignore ledger: @anthropic-ai/sdk 0.81.0 under the pinned claude-agent-sdk — drop on the next harness bump (by 2026-11-30)

Open Beginner friendly
#2,754 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
133k
Forks
19.9k
Avg merge
18h 46m
Merged PRs (30d)
26

Description

The v1.78.0.0 wave's OSV pass suppresses GHSA-p7fg-763f-g4gf (@anthropic-ai/sdk 0.81.0, 4.8 MEDIUM) with `ignoreUntil = 2026-11-30` in `.osv-scanner.toml`.

Why not fixed in the wave: the vulnerable node is nested under @anthropic-ai/claude-agent-sdk@0.2.117, which is deliberately exact-pinned for eval-harness stability (the v1.77 wave pinned the whole harness after repeated CLI-drift breakage) and declares ^0.81.0 — a 0.x caret, so the 0.91.1 fix is out of range and forcing it via overrides would violate the harness pin for a MEDIUM.

Upgrade trigger: the next deliberate claude-agent-sdk bump. When that pin moves, drop this ignore in the same commit. If the ignoreUntil expiry (2026-11-30) fires first, the weekly OSV lane goes red and this decision must be re-justified or re-dated here.

Contributor guide

Open the contributing guide

Research direction

Start with .osv-scanner.toml and verify the GHSA-p7fg-763f-g4gf ignore and expiry. When the exact claude-agent-sdk pin is deliberately bumped, remove that ignore in the same commit and run the weekly OSV lane to confirm it remains green.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Refactor
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.