Repository navigation
build(deps): override katex 0.18.2 and smol-toml 1.9.0 - #48
Merged
Merged
Conversation
The smol-toml 1.7.1 pin from alert #3 still matches GHSA-r4xh-jqrq-34v2, and katex 0.16.47 is below GHSA-238p-pmpm-9mq7. Force the patched releases through npm overrides so markdownlint-cli2 0.23.3 stays put. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Summary
katexto 0.18.2 andsmol-tomlto 1.9.0.package-lock.jsonresolves those two dev packages and nothing else.markdownlint-cli2stays 0.23.3. The CI stepnpm audit --omit=dev --audit-level=moderateis unchanged.markdownlint-cli2dev chain. The existingsmol-toml1.7.1 override (PR build(deps): override smol-toml to 1.7.1 (Dependabot alert #3) #34, alert build(deps): bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 #3) is still inside GHSA-r4xh-jqrq-34v2 (<=1.8.0), so Dependabot cannot move it.katex0.16.47 is inside GHSA-238p-pmpm-9mq7 (<0.18.2).micromark-extension-math3.1.0 (latest, pinned by markdownlint 0.41.1) requestskatex@^0.16.0, and markdownlint-cli2 0.23.3 (latest) requestssmol-toml@1.8.0, so neither patched release is reachable without an override. PR ci: bump axios to 1.20.0 and audit production dependencies #47 left these in place becausebraceshas no patched release andnpm audit fix --forcewould downgrade markdownlint-cli2. These two advisories now have patched targets that do not require that downgrade.Lockfile version delta
katex(node_modules/katex)smol-toml(node_modules/smol-toml)uuidstays overridden at 11.1.1. No other locked package version changed.Verification
Local commands on this tip (Node v22.14.0, npm 10.9.7):
npm ci --ignore-scripts— exit 0. Added 151 packages.npm lsshowskatex@0.18.2 overriddenandsmol-toml@1.9.0 overriddenunder markdownlint-cli2 0.23.3.npm run check— exit 0. 20 tests, 20 pass, 0 fail.npm run lint:markdown— exit 0. markdownlint-cli2 v0.23.3 (markdownlint v0.41.1), 9 files, 0 issues. That command loads both packages: the math extension imports KaTeX, and the CLI statically importssmol-tomlparse.katex.renderToStringon inline and display math, andmarkdownlint-cli2/parsers/tomlon a sample config, both succeeded on the overridden versions.npm audit --omit=dev --audit-level=moderate— exit 0.found 0 vulnerabilities.npm audit --audit-level=moderate— exit 1 (dev-onlybraces; not the CI step).katexandsmol-tomlare gone. Output:npm audit --omit=dev --audit-level=moderateexits 0; repository validator runs in CI)CHANGELOG.md(no user-visible change)Security impact
Dev-only
katexmoves from 0.16.47 to 0.18.2 (GHSA-238p-pmpm-9mq7, alert #7) and dev-onlysmol-tomlmoves from 1.7.1 to 1.9.0 (GHSA-r4xh-jqrq-34v2, alert #8; 1.9.0 still includes the 1.7.1 fix for GHSA-7w5x-hrqm-74c2). The runtime audit is unchanged and still exits 0.braces(GHSA-vfj7-8cjw-p6xm) stays unfixed: there is still no patched release, and clearing it still requires a breaking downgrade of markdownlint-cli2. Authentication, port exposure, command execution, protocol parsing, output handling, services, and licensing are unchanged.