Skip to content

fix(docs): lint Markdown without markdownlint-cli2 to drop vulnerable braces - #163

Merged
joeblau merged 3 commits into
mainfrom
fix/docs-drop-markdownlint-cli2
Oct 7, 2026
Merged

joeblau merged 3 commits into
mainfrom
fix/docs-drop-markdownlint-cli2

Conversation

@joeblau

@joeblau joeblau commented Oct 6, 2026

Copy link
Copy Markdown

The Security workflow fails on every PR and on main's weekly scan because of GHSA-vfj7-8cjw-p6xm: braces ≤ 3.0.3 has a stack-exhaustion DoS and no patched release. Its only path into the lockfile was markdownlint-cli2's file discovery — globby → fast-glob → micromatch → braces — and every package in that chain is already at its latest version, so no upgrade can fix it.

  • Run the markdownlint rule engine directly from apps/docs/scripts/lint-markdown.ts, finding files with Bun.Glob. It uses markdownlint 0.41.1, the engine version markdownlint-cli2 0.23.3 already ran.
  • Keep the rules, configuration (moved from .markdownlint-cli2.jsonc with its comments), linted files, file:line[:column] severity rule description output, and error-only exit status the same as the CLI.
  • Drop .markdownlint-cli2.jsonc from the docs workflow's path filters. 37 packages leave bun.lock, including braces, micromatch, fast-glob, and globby.

Validation: on a copy of the docs with 13 injected violations across two files (plus bait for the disabled MD013/MD033/MD028 rules and an inline markdownlint-disable-next-line), the old CLI and the new script linted the same 19 files and reported the identical set of file/line/rule findings. bun run check:docs, the docs bun run check (fumadocs-mdx, next typegen, tsc --noEmit), the 10 docs helper tests, Biome, and bun install --frozen-lockfile pass; braces no longer appears in bun.lock.

🤖 Generated with Claude Code

… braces

The dependency scan fails on GHSA-vfj7-8cjw-p6xm (braces <= 3.0.3, stack-exhaustion
DoS, no patched release). The only path to braces was markdownlint-cli2's file
discovery: globby -> fast-glob -> micromatch -> braces, all already at their latest
versions, so no upgrade can fix it.

Run the markdownlint rule engine (0.41.1, the version the CLI already used) from a
small Bun script that finds files with Bun.Glob. Rules, configuration, linted files,
output format, and exit status match the CLI; 37 packages leave the lockfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
joeblau added a commit that referenced this pull request Oct 6, 2026
Pin patched releases of the docs app's vulnerable transitive dependencies
through root package.json overrides (all published more than three days
ago, so bunfig.toml's minimumReleaseAge still holds):

- katex 0.16.47 -> 0.18.11 (GHSA-238p-pmpm-9mq7)
- sharp 0.35.4 -> 0.35.5 (GHSA-wq5f-xc86-pv6w)
- smol-toml 1.8.0 -> 1.9.0 (GHSA-r4xh-jqrq-34v2)
- source-map-js 1.2.1 -> 1.2.2 (GHSA-68fv-2mgg-jv7q)

braces has no patched release for GHSA-vfj7-8cjw-p6xm, so add an expiring,
single-advisory ignore in osv-scanner.toml and pass it to the Security
workflow explicitly. braces is reachable only through markdownlint-cli2,
which #163 removes.

Also apply the Biome formatting that apps/docs/app/layout.tsx was missing
on main, so the format check passes.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
joeblau and others added 2 commits October 7, 2026 15:36
With markdownlint-cli2 gone, braces and smol-toml no longer appear in bun.lock.
Remove the GHSA-vfj7-8cjw-p6xm ignore, which was osv-scanner.toml's only entry, so
delete the file and its --config argument in the Security workflow, and drop the
smol-toml override. Keep the katex override: markdownlint itself still pulls katex
through micromark-extension-math. The sharp and source-map-js overrides stay.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joeblau

joeblau commented Oct 7, 2026

Copy link
Copy Markdown
Author

Merged origin/main into this branch (no rebase). The only conflict was bun.lock: I took main's version and regenerated it with bun install. The result removes the same packages this PR originally removed (braces, micromatch, fast-glob, globby and the rest of markdownlint-cli2's tree). bunfig.toml keeps minimumReleaseAge.

Follow-up cleanup from #165 (62d9abb):

  • braces no longer appears in bun.lock, so the GHSA-vfj7-8cjw-p6xm ignore is gone. It was the only entry, so I deleted osv-scanner.toml and removed --config=osv-scanner.toml from the Security workflow.
  • smol-toml no longer appears either, so I dropped its override.
  • I kept the katex override because markdownlint 0.41.1 still pulls katex in through micromark-extension-math. The sharp and source-map-js overrides also stay.

Local runs that passed: bun install --frozen-lockfile, bun run check, bun run test:offline (2072 pass, 0 fail), bun run build, and the docs app's bun run build and bun run check.

🤖 Generated with Claude Code

@joeblau
joeblau merged commit 02f4bde into main Oct 7, 2026
6 checks passed
@joeblau
joeblau deleted the fix/docs-drop-markdownlint-cli2 branch October 7, 2026 07:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant