Skip to content

Conversation

@Ankush-Pathak
Copy link
Member

@Ankush-Pathak Ankush-Pathak commented Nov 4, 2025

GHSA-29xp-372q-xqph in npm was initally resolved as pending-upstream-fix. I have since discovered upstream discussions that establish that npm does not use the vulnerable code path. See nodejs/node#60430 (comment) and nodejs/node#60012 (comment)
Proposing adding a false-positive-determination event.

@Ankush-Pathak Ankush-Pathak requested a review from a team November 4, 2025 09:34
@dnegreira dnegreira added this pull request to the merge queue Nov 4, 2025
Merged via the queue into wolfi-dev:main with commit ce8ef23 Nov 4, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants