Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Conversation

@Ankush-Pathak
Copy link
Member

@Ankush-Pathak Ankush-Pathak commented Nov 4, 2025

GHSA-29xp-372q-xqph in npm was initally resolved as pending-upstream-fix. I have since discovered upstream discussions that establish that npm does not use the vulnerable code path. See nodejs/node#60430 (comment) and nodejs/node#60012 (comment)
Proposing adding a false-positive-determination event.

Signed-off-by: Ankush Pathak <ankush.pathak@chainguard.dev>
@Ankush-Pathak Ankush-Pathak requested a review from a team November 4, 2025 09:34
@dnegreira dnegreira added this pull request to the merge queue Nov 4, 2025
Merged via the queue into wolfi-dev:main with commit ce8ef23 Nov 4, 2025
4 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants