Repository navigation
fix(deps): override js-yaml to 5.4.1 - #160
Draft
joshuaboys wants to merge 1 commit into
Draft
joshuaboys wants to merge 1 commit into
joshuaboys wants to merge 1 commit into
Conversation
Force patched js-yaml into markdownlint-cli's tree so Dependabot alert #57 (GHSA-r3ph-w7gj-g6xm) resolves. markdownlint-cli@0.49.1 pins ~5.2.1, which cannot reach 5.4.1; pnpm 11 reads overrides from pnpm-workspace.yaml, not package.json.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependabot Alert Fix
Alerts addressed: #57
Severity: medium
Strategy: Override (
js-yaml@^5.4.1in rootpnpm-workspace.yaml)What was vulnerable
js-yaml@5.2.3viamarkdownlint-cli@0.49.1(devDependency). GHSA-r3ph-w7gj-g6xm:maxTotalMergeKeysdoes not count empty merge-source mappings, so a crafted YAML document can burn CPU without hitting the limit.This repo lints with
.markdownlint.json, not YAML config. markdownlint-cli callsjs-yaml.load()with default options; v5 has merge keys off by default, so the DoS path is not exercised here. The override still closes the advisory.What was done
pnpm-workspace.yamlwithoverrides: { js-yaml: ^5.4.1 }.package.json#pnpm.overrides(it warned and ignored that field), matching the MCP package's existing override home.pnpm-lock.yaml; the tree now resolvesjs-yaml@5.4.2(latest patch on the 5.4.1 advisory).markdownlint-cli@0.49.1is still latest and pinsjs-yaml@~5.2.1, so a parent bump cannot reach 5.4.x..only;mcp/remains its own pnpm project.Research sources
package.json#pnpmis no longer read; overrides live inpnpm-workspace.yamljs-yaml: ~5.2.1What was tested
npx markdownlint-cli "**/*.md"): pass./test/run.sh): passanvil-plan-spec(devDependency tree)Escalated items
(none)