osv-scanner fix erroneously reports blocked vulnerabilities as fixed
- Dominant language
- Go
- Stars
- 11k
- Forks
- 792
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 48
Description
# `osv-scanner fix` erroneously reports blocked vulnerabilities as fixed
## Environment
```
osv-scanner version: 2.5.0
```
Ecosystem: npm, ecosystem tooling `npm@10.9.8` / `node@v22.23.1`.
## Summary
`osv-scanner fix` incorrectly reports vulnerabilities as fixed when an npm package is pinned by a top-level `package.json` `overrides` entry.
In this case, the tool returns `"packageUpdates": null` and leaves both input files unchanged, but still lists every targeted advisory in `"fixed"`. The vulnerable package remains installed.
## Reproduction
Files attached:
- `package.json` / `package-lock.json` — unchanged before and after `fix`
- `package.json.orig` / `package-lock.json.orig` — copies for comparison
- `result.json` — the actual `-f json` output from the run described below
`package.json`:
```json
{
"name": "minimal-repro-transitive-override",
"version": "1.0.0",
"license": "MIT",
"dependencies": {
"node-gyp": "12.4.0"
},
"overrides": {
"tar": "7.5.16"
}
}
```
`tar` is reachable transitively through `node-gyp@12.4.0` and pinned to vulnerable `7.5.16` by the top-level `overrides` block. The following advisories affect `7.5.16` and are fixed in `tar@7.5.22`:
- GHSA-23hp-3jrh-7fpw
- GHSA-8x88-c5mf-7j5w
- GHSA-gvwx-54wh-qm9j
- GHSA-r292-9mhp-454m
- GHSA-w8wr-v893-vjvp
Steps:
```bash
npm install --package-lock-only --ignore-scripts
osv-scanner fix -M package.json -L package-lock.json --apply-top 1 -f json | tee result.json
```
## Observed output
```json
{
"path": "package.json",
"ecosystem": "npm",
"strategy": "relax",
"vulnerabilities": [
{
"id": "GHSA-23hp-3jrh-7fpw",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-8x88-c5mf-7j5w",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-gvwx-54wh-qm9j",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-r292-9mhp-454m",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-w8wr-v893-vjvp",
"packages": [{ "name": "tar", "version": "7.5.16" }]
}
],
"patches": [
{
"packageUpdates": null,
"fixed": [
{
"id": "GHSA-23hp-3jrh-7fpw",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-8x88-c5mf-7j5w",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-gvwx-54wh-qm9j",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-r292-9mhp-454m",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-w8wr-v893-vjvp",
"packages": [{ "name": "tar", "version": "7.5.16" }]
}
]
}
]
}
```
`packageUpdates: null` indicates that the tool could not compute an update. However, the same patch entry still lists all five advisories as fixed.
## Confirming nothing actually changed
```bash
$ cmp package.json.orig package.json && echo "package.json: IDENTICAL"
package.json: IDENTICAL
$ cmp package-lock.json.orig package-lock.json && echo "package-lock.json: IDENTICAL"
package-lock.json: IDENTICAL
```
`package-lock.json` still contains vulnerable `tar@7.5.16` after the command completes.
## Expected output
The expected result for an unavailable patch is:
```json
{
"path": "package.json",
"ecosystem": "npm",
"strategy": "relax",
"vulnerabilities": [
{
"id": "GHSA-23hp-3jrh-7fpw",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-8x88-c5mf-7j5w",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-gvwx-54wh-qm9j",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-r292-9mhp-454m",
"packages": [{ "name": "tar", "version": "7.5.16" }]
},
{
"id": "GHSA-w8wr-v893-vjvp",
"packages": [{ "name": "tar", "version": "7.5.16" }]
}
],
"patches": [
{
"packageUpdates": null,
"fixed": [ ]
}
]
}
```
It should not include `"fixed"` unless the command applies an update and verifies that the advisories are resolved. If the override prevents an update, report the advisories as unresolved and make the blocking condition clear in the output.
[package-lock.json](https://github.com/user-attachments/files/31037916/package-lock.json)
[package.json](https://github.com/user-attachments/files/31037915/package.json)
Contributor guide
Assessment
This issue has not been assessed yet.