Skip to content

chore(deps-dev): override smol-toml and katex to close dev-only alerts - #257

Merged
docdyhr merged 1 commit into
mainfrom
fix/deps-dev-smol-toml-katex
Oct 7, 2026
Merged

docdyhr merged 1 commit into
mainfrom
fix/deps-dev-smol-toml-katex

Conversation

@docdyhr

@docdyhr docdyhr commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Pull Request

Description

Closes two of the five dev-only Dependabot alerts opened on 2026-10-07. In both cases the patched release is outside the declared range of a parent that's already at its latest version, so Dependabot can't open a bump PR itself.

Alert Package Severity Change Why an override
#77 smol-toml medium (GHSA-r4xh-jqrq-34v2, quadratic-time parse) 1.7.2 → 1.9.0 markdownlint-cli@0.49.1 (latest) pins ~1.7.0
#76 katex low (prototype-pollution trust bypass) 0.16.47 → 0.18.10 micromark-extension-math@3.1.0 (latest) declares ^0.16.0

Both are scoped overrides, following the existing markdownlint-cli → js-yaml and cosmiconfig → js-yaml entries.

Not fixable here: #71 http-cache-semantics (high, no patched release) and #74 postcss-selector-parser (medium) are both bundled inside the npm CLI that @semantic-release/npm uses (inBundle: true). Root overrides can't reach bundled dependencies. @semantic-release/npm requires npm ^11.6.2, and even the latest 11.x (11.21.0, checked from its published tarball) still bundles postcss-selector-parser@7.1.4 and http-cache-semantics@4.2.0. Both are dev/release-time only, and the production audit gate is unaffected.

Type of Change

  • 🔒 Security fix (dev dependencies only — no runtime or published-package change)

Changes Made

  • package.json: overrides["markdownlint-cli"]["smol-toml"] = ">=1.9.0 <2.0.0"; new overrides["micromark-extension-math"]["katex"] = ">=0.18.2 <0.19.0"
  • package-lock.json: smol-toml, katex, and katex's own nested commander (8.3.0 → 15.0.0) — nothing else

Testing

Tests Performed

  • Unit tests pass: npm test (2511 tests) and full npx vitest run (90 files / 2566 tests)
  • TypeScript compilation (npm run build, npm run typecheck)
  • Linting passes (npm run lint, npm run format:check)
  • Manual testing performed

Test Cases

  1. npm run lint:md passes, with output identical before and after the change
  2. smol-toml 1.9 path: markdownlint-cli with a .toml config setting MD013.line_length = 10 correctly reported a 50-char line, so the TOML config was parsed and applied
  3. katex reachability: markdownlint/lib/micromark-parse.mjs imports only { math } from micromark-extension-math. katex is imported solely by lib/html.js (mathHtml), which markdownlint never loads, so katex 0.18 is never executed here
  4. npm audit: smol-toml and katex are clean. The production audit gate has 0 findings
  5. Pre-commit (384 security tests) and pre-push (full batched suite + audit gate) hooks passed

Breaking Changes

None. Dev-only, and no runtime or published-package change. katex's nested commander@15 declares node >=22.12.0, which matches this repo's own Node 22.12+ requirement since 4.0.0. It's only used by katex's CLI, which nothing runs.

Documentation

Security

  • No sensitive information committed
  • Dependencies updated to secure versions

Additional Notes

The scoped overrides can be removed once markdownlint-cli widens its smol-toml range and micromark-extension-math moves to katex ≥0.18.2.

🤖 Generated with Claude Code

Summary by Sourcery

Override vulnerable development dependency versions while preserving production and runtime dependency behavior.

Bug Fixes:

  • Update development-only dependency resolutions to patched versions of smol-toml and katex, addressing their reported security vulnerabilities.

Tests:

  • Verify the dependency updates with the existing unit, type-checking, linting, formatting, audit, and hook checks.

Chores:

  • Refresh the lockfile for the overridden dependency versions and their transitive changes.

Close two Dependabot alerts in markdownlint-cli's dependency tree whose
patched releases sit outside the parents' declared ranges:

- smol-toml 1.7.2 -> 1.9.0 (alert #77, medium, GHSA-r4xh-jqrq-34v2:
  quadratic-time parse). markdownlint-cli 0.49.1 (latest) pins ~1.7.0.
  Added to the existing scoped markdownlint-cli override, next to js-yaml.
  smol-toml is only used to read .toml config files; verified a TOML
  config still parses and applies under 1.9.0.
- katex 0.16.47 -> 0.18.10 (alert #76, low, prototype-pollution trust
  bypass). micromark-extension-math 3.1.0 (latest) declares ^0.16.0.
  Scoped override under micromark-extension-math. markdownlint imports
  only its `math` syntax extension; katex is loaded solely by `mathHtml`,
  so it is never executed here. katex's nested commander moves 8 -> 15
  (CLI only, engines node >=22.12.0, matching this repo's requirement).

lint:md output is identical before and after. Alerts #71
(http-cache-semantics) and #74 (postcss-selector-parser) live inside the
npm CLI bundled with @semantic-release/npm; overrides cannot reach them
and npm 11.21.0 (latest 11.x) still bundles the affected versions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 11:23
@strix-security

strix-security Bot commented Oct 7, 2026

Copy link
Copy Markdown

Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.

So far, Strix has reviewed 30 pull requests across this workspace.

@sourcery-ai

sourcery-ai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Closes the smol-toml and katex dev-only security alerts by adding narrowly scoped npm overrides and updating the lockfile, without changing production dependencies, runtime behavior, or published package contents.

File-Level Changes

Change Details Files
Add scoped dependency overrides to force patched dev-only transitive versions while preserving existing parent ranges.
  • Override markdownlint-cli’s smol-toml dependency to the secure 1.9.x range.
  • Override micromark-extension-math’s katex dependency to the secure 0.18.x range.
  • Keep overrides scoped to the affected parent packages rather than changing global resolution behavior.
package.json
Regenerate the lockfile to record the overridden packages and their compatible transitive dependency updates.
  • Update smol-toml from 1.7.2 to 1.9.0.
  • Update katex from 0.16.47 to 0.18.10.
  • Update katex’s nested commander dependency from 8.3.0 to 15.0.0.
package-lock.json

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@github-actions github-actions Bot added the config label Oct 7, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T11:25:39.373339Z 6e4f289 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The scoped overrides and lockfile updates are consistent, compatible with the repository’s Node.js floor, and limited to development dependencies.

Review effort: Balanced
Findings: None

What changed in this PR

Updates development-only dependency overrides to resolve two security alerts without affecting runtime dependencies.

Changes:

  • Overrides smol-toml and katex with patched versions.
  • Refreshes lockfile resolutions, including KaTeX’s nested commander.
File Description
package.json Adds scoped security overrides.
package-lock.json Locks patched dependency versions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@docdyhr
docdyhr merged commit bb10b1d into main Oct 7, 2026
26 checks passed
@docdyhr
docdyhr deleted the fix/deps-dev-smol-toml-katex branch October 7, 2026 11:33
@docdyhr

docdyhr commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

🎉 This PR is included in version 4.0.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants