AFTERMERGEPost-merge agent
Board/AM-1838
Held by agentCritical risk

chore: bump @northline/invoice-pdf to 4.2.0

fieldclear/billing!461 · chore/invoice-pdf-4-2-0 → main · Chris Alvarez · e18d77b

Merged Sep 30, 21:40 UTC

The agent held this merge.

Held before staging. DEMO-CVE-1184 in libxmljs2 is reachable from customer invoice rendering.

AfterMerge agent

Held before staging. DEMO-CVE-1184 in libxmljs2 is reachable from customer invoice rendering.

Why this stage

Dependencies

invoice-pdf 4.2.0 pulls libxmljs2 0.35.0. The advisory is a simulated XXE in the XML parser. billing/src/invoices/render.ts passes customer-supplied PO XML into that parser when a commercial job is invoiced. The vulnerable function is reachable. I am not deploying this to staging.

Tool calls

  • gemnasium.audit

    fail · 18s

    lockfile=package-lock.json

    DEMO-CVE-1184 critical reachable

  • agent.reachability

    ok · 6s

    pkg=libxmljs2 entry=render.ts

    reachable via parseXml

Policy

FieldClear policy: critical findings hold before staging. Medium and high risk stop for a named approver. Low risk with green smoke may auto-promote, and field ops is still notified.