Skip to content

fix(deps): resolve OSV-reported advisories in the lockfile - #165

Merged
joeblau merged 1 commit into
mainfrom
fix/deps-osv-advisories
Oct 6, 2026
Merged

joeblau merged 1 commit into
mainfrom
fix/deps-osv-advisories

Conversation

@joeblau

@joeblau joeblau commented Oct 6, 2026

Copy link
Copy Markdown

Summary

The scheduled Security workflow has been red on main since 2026-10-05: OSV-Scanner reports five advisories in bun.lock, all in the docs app's transitive dependencies. This PR clears all five.

Advisory Package Before After How
GHSA-238p-pmpm-9mq7 katex (via markdownlint → micromark-extension-math) 0.16.47 0.18.11 overrides
GHSA-wq5f-xc86-pv6w sharp (optional dep of next) 0.35.4 0.35.5 overrides
GHSA-r4xh-jqrq-34v2 smol-toml (via markdownlint-cli2) 1.8.0 1.9.0 overrides
GHSA-68fv-2mgg-jv7q source-map-js (via postcss) 1.2.1 1.2.2 overrides
GHSA-vfj7-8cjw-p6xm braces (via markdownlint-cli2 → globby → micromatch) 3.0.3 3.0.3 ignored in osv-scanner.toml, expires 2026-12-31
  • Every pinned version was published more than three days ago, so minimumReleaseAge = 259200 in bunfig.toml stays as it is.
  • braces has no patched release (<= 3.0.3 is affected, and 3.0.3 is the latest). An override can't fix it, so osv-scanner.toml ignores that one advisory ID until a set date, with a written reason. The Security workflow now passes the config with --config=osv-scanner.toml.
  • apps/docs/app/layout.tsx gets the Biome formatting that main (68cb6d2) was missing. Without it, bun run check:format fails on every PR.

Relation to #163

#163 (fix/docs-drop-markdownlint-cli2) removes markdownlint-cli2, which also takes braces, smol-toml and katex out of the lockfile. Its quality and perf checks are still failing, so this PR gets main green without waiting for it. Once #163 lands, the braces entry in osv-scanner.toml and the katex and smol-toml overrides will no longer match anything and can be deleted. The sharp and source-map-js overrides are still needed after that.

Test plan

  • Local osv-scanner v2.3.8 (the version the workflow pins) with the workflow's arguments: 5 findings before this change, "No issues found" after
  • bun run check (format, lint, docs content incl. markdownlint, types, ts7, jsdoc, exports, imports)
  • bun run test:offline: 1974 pass, 0 fail
  • bun run build
  • cd apps/docs && bun run build && bun run check && bun run test

🤖 Generated with Claude Code

Pin patched releases of the docs app's vulnerable transitive dependencies
through root package.json overrides (all published more than three days
ago, so bunfig.toml's minimumReleaseAge still holds):

- katex 0.16.47 -> 0.18.11 (GHSA-238p-pmpm-9mq7)
- sharp 0.35.4 -> 0.35.5 (GHSA-wq5f-xc86-pv6w)
- smol-toml 1.8.0 -> 1.9.0 (GHSA-r4xh-jqrq-34v2)
- source-map-js 1.2.1 -> 1.2.2 (GHSA-68fv-2mgg-jv7q)

braces has no patched release for GHSA-vfj7-8cjw-p6xm, so add an expiring,
single-advisory ignore in osv-scanner.toml and pass it to the Security
workflow explicitly. braces is reachable only through markdownlint-cli2,
which #163 removes.

Also apply the Biome formatting that apps/docs/app/layout.tsx was missing
on main, so the format check passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joeblau
joeblau merged commit 1bffff5 into main Oct 6, 2026
6 checks passed
@joeblau
joeblau deleted the fix/deps-osv-advisories branch October 6, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant