Repository navigation
chore(deps-dev): override smol-toml and katex to close dev-only alerts - #257
Conversation
Close two Dependabot alerts in markdownlint-cli's dependency tree whose patched releases sit outside the parents' declared ranges: - smol-toml 1.7.2 -> 1.9.0 (alert #77, medium, GHSA-r4xh-jqrq-34v2: quadratic-time parse). markdownlint-cli 0.49.1 (latest) pins ~1.7.0. Added to the existing scoped markdownlint-cli override, next to js-yaml. smol-toml is only used to read .toml config files; verified a TOML config still parses and applies under 1.9.0. - katex 0.16.47 -> 0.18.10 (alert #76, low, prototype-pollution trust bypass). micromark-extension-math 3.1.0 (latest) declares ^0.16.0. Scoped override under micromark-extension-math. markdownlint imports only its `math` syntax extension; katex is loaded solely by `mathHtml`, so it is never executed here. katex's nested commander moves 8 -> 15 (CLI only, engines node >=22.12.0, matching this repo's requirement). lint:md output is identical before and after. Alerts #71 (http-cache-semantics) and #74 (postcss-selector-parser) live inside the npm CLI bundled with @semantic-release/npm; overrides cannot reach them and npm 11.21.0 (latest 11.x) still bundles the affected versions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here. So far, Strix has reviewed 30 pull requests across this workspace. |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideCloses the smol-toml and katex dev-only security alerts by adding narrowly scoped npm overrides and updating the lockfile, without changing production dependencies, runtime behavior, or published package contents. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The scoped overrides and lockfile updates are consistent, compatible with the repository’s Node.js floor, and limited to development dependencies.
Review effort: Balanced
Findings: None
What changed in this PR
Updates development-only dependency overrides to resolve two security alerts without affecting runtime dependencies.
Changes:
- Overrides
smol-tomlandkatexwith patched versions. - Refreshes lockfile resolutions, including KaTeX’s nested
commander.
| File | Description |
|---|---|
package.json |
Adds scoped security overrides. |
package-lock.json |
Locks patched dependency versions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🎉 This PR is included in version 4.0.4 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Pull Request
Description
Closes two of the five dev-only Dependabot alerts opened on 2026-10-07. In both cases the patched release is outside the declared range of a parent that's already at its latest version, so Dependabot can't open a bump PR itself.
smol-tomlmarkdownlint-cli@0.49.1(latest) pins~1.7.0katexmicromark-extension-math@3.1.0(latest) declares^0.16.0Both are scoped overrides, following the existing
markdownlint-cli → js-yamlandcosmiconfig → js-yamlentries.Not fixable here: #71
http-cache-semantics(high, no patched release) and #74postcss-selector-parser(medium) are both bundled inside thenpmCLI that@semantic-release/npmuses (inBundle: true). Rootoverridescan't reach bundled dependencies.@semantic-release/npmrequiresnpm ^11.6.2, and even the latest 11.x (11.21.0, checked from its published tarball) still bundlespostcss-selector-parser@7.1.4andhttp-cache-semantics@4.2.0. Both are dev/release-time only, and the production audit gate is unaffected.Type of Change
Changes Made
package.json:overrides["markdownlint-cli"]["smol-toml"] = ">=1.9.0 <2.0.0"; newoverrides["micromark-extension-math"]["katex"] = ">=0.18.2 <0.19.0"package-lock.json:smol-toml,katex, and katex's own nestedcommander(8.3.0 → 15.0.0) — nothing elseTesting
Tests Performed
npm test(2511 tests) and fullnpx vitest run(90 files / 2566 tests)npm run build,npm run typecheck)npm run lint,npm run format:check)Test Cases
npm run lint:mdpasses, with output identical before and after the change.tomlconfig settingMD013.line_length = 10correctly reported a 50-char line, so the TOML config was parsed and appliedmarkdownlint/lib/micromark-parse.mjsimports only{ math }frommicromark-extension-math. katex is imported solely bylib/html.js(mathHtml), which markdownlint never loads, so katex 0.18 is never executed herenpm audit:smol-tomlandkatexare clean. The production audit gate has 0 findingsBreaking Changes
None. Dev-only, and no runtime or published-package change. katex's nested
commander@15declaresnode >=22.12.0, which matches this repo's own Node 22.12+ requirement since 4.0.0. It's only used by katex's CLI, which nothing runs.Documentation
chore(deps-dev), like chore(deps-dev): bump axios from 1.18.1 to 1.20.0 in the npm_and_yarn group across 1 directory #254 and chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in the npm_and_yarn group across 1 directory #256, so this won't cut a release.Security
Additional Notes
The scoped overrides can be removed once
markdownlint-cliwidens itssmol-tomlrange andmicromark-extension-mathmoves to katex ≥0.18.2.🤖 Generated with Claude Code
Summary by Sourcery
Override vulnerable development dependency versions while preserving production and runtime dependency behavior.
Bug Fixes:
Tests:
Chores: