Skip to content

fix(deps): override js-yaml to 5.4.1 - #160

Draft
joshuaboys wants to merge 1 commit into
mainfrom
dependabot/fix/js-yaml
Draft

joshuaboys wants to merge 1 commit into
mainfrom
dependabot/fix/js-yaml

Conversation

@joshuaboys

Copy link
Copy Markdown
Contributor

Dependabot Alert Fix

Alerts addressed: #57
Severity: medium
Strategy: Override (js-yaml@^5.4.1 in root pnpm-workspace.yaml)

What was vulnerable

js-yaml@5.2.3 via markdownlint-cli@0.49.1 (devDependency). GHSA-r3ph-w7gj-g6xm: maxTotalMergeKeys does not count empty merge-source mappings, so a crafted YAML document can burn CPU without hitting the limit.

This repo lints with .markdownlint.json, not YAML config. markdownlint-cli calls js-yaml.load() with default options; v5 has merge keys off by default, so the DoS path is not exercised here. The override still closes the advisory.

What was done

  • Added root pnpm-workspace.yaml with overrides: { js-yaml: ^5.4.1 }.
  • pnpm 11 no longer reads package.json#pnpm.overrides (it warned and ignored that field), matching the MCP package's existing override home.
  • Refreshed pnpm-lock.yaml; the tree now resolves js-yaml@5.4.2 (latest patch on the 5.4.1 advisory).
  • markdownlint-cli@0.49.1 is still latest and pins js-yaml@~5.2.1, so a parent bump cannot reach 5.4.x.
  • Root importers stay . only; mcp/ remains its own pnpm project.

Research sources

What was tested

  • Build: n/a (lockfile override only)
  • markdownlint (npx markdownlint-cli "**/*.md"): pass
  • CLI suite (./test/run.sh): pass
  • Affected packages: root anvil-plan-spec (devDependency tree)
  • Pre-existing failures (not caused by this change): none

Escalated items

(none)

Force patched js-yaml into markdownlint-cli's tree so Dependabot
alert #57 (GHSA-r3ph-w7gj-g6xm) resolves. markdownlint-cli@0.49.1
pins ~5.2.1, which cannot reach 5.4.1; pnpm 11 reads overrides from
pnpm-workspace.yaml, not package.json.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant