Repository navigation
fix(docs): lint Markdown without markdownlint-cli2 to drop vulnerable braces - #163
Merged
Merged
Conversation
… braces The dependency scan fails on GHSA-vfj7-8cjw-p6xm (braces <= 3.0.3, stack-exhaustion DoS, no patched release). The only path to braces was markdownlint-cli2's file discovery: globby -> fast-glob -> micromatch -> braces, all already at their latest versions, so no upgrade can fix it. Run the markdownlint rule engine (0.41.1, the version the CLI already used) from a small Bun script that finds files with Bun.Glob. Rules, configuration, linted files, output format, and exit status match the CLI; 37 packages leave the lockfile. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 6, 2026
joeblau
added a commit
that referenced
this pull request
Oct 6, 2026
Pin patched releases of the docs app's vulnerable transitive dependencies through root package.json overrides (all published more than three days ago, so bunfig.toml's minimumReleaseAge still holds): - katex 0.16.47 -> 0.18.11 (GHSA-238p-pmpm-9mq7) - sharp 0.35.4 -> 0.35.5 (GHSA-wq5f-xc86-pv6w) - smol-toml 1.8.0 -> 1.9.0 (GHSA-r4xh-jqrq-34v2) - source-map-js 1.2.1 -> 1.2.2 (GHSA-68fv-2mgg-jv7q) braces has no patched release for GHSA-vfj7-8cjw-p6xm, so add an expiring, single-advisory ignore in osv-scanner.toml and pass it to the Security workflow explicitly. braces is reachable only through markdownlint-cli2, which #163 removes. Also apply the Biome formatting that apps/docs/app/layout.tsx was missing on main, so the format check passes. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…nlint-cli2 # Conflicts: # bun.lock
With markdownlint-cli2 gone, braces and smol-toml no longer appear in bun.lock. Remove the GHSA-vfj7-8cjw-p6xm ignore, which was osv-scanner.toml's only entry, so delete the file and its --config argument in the Security workflow, and drop the smol-toml override. Keep the katex override: markdownlint itself still pulls katex through micromark-extension-math. The sharp and source-map-js overrides stay. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Author
|
Merged Follow-up cleanup from #165 (62d9abb):
Local runs that passed: 🤖 Generated with Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Security workflow fails on every PR and on main's weekly scan because of GHSA-vfj7-8cjw-p6xm: braces ≤ 3.0.3 has a stack-exhaustion DoS and no patched release. Its only path into the lockfile was markdownlint-cli2's file discovery —
globby → fast-glob → micromatch → braces— and every package in that chain is already at its latest version, so no upgrade can fix it.apps/docs/scripts/lint-markdown.ts, finding files withBun.Glob. It uses markdownlint 0.41.1, the engine version markdownlint-cli2 0.23.3 already ran..markdownlint-cli2.jsoncwith its comments), linted files,file:line[:column] severity rule descriptionoutput, and error-only exit status the same as the CLI..markdownlint-cli2.jsoncfrom the docs workflow's path filters. 37 packages leavebun.lock, including braces, micromatch, fast-glob, and globby.Validation: on a copy of the docs with 13 injected violations across two files (plus bait for the disabled MD013/MD033/MD028 rules and an inline
markdownlint-disable-next-line), the old CLI and the new script linted the same 19 files and reported the identical set of file/line/rule findings.bun run check:docs, the docsbun run check(fumadocs-mdx, next typegen,tsc --noEmit), the 10 docs helper tests, Biome, andbun install --frozen-lockfilepass;bracesno longer appears inbun.lock.🤖 Generated with Claude Code