Repository navigation
Bump markdown-it and js-yaml to close Dependabot alerts #73 and #74 - #120
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📜 Recent review details⏰ Context from checks skipped due to timeout. (1)
🔇 Additional comments (3)
📝 WalkthroughWalkthroughThe Markdown lint configuration excludes ChangesMarkdown lint exclusion
Dependency overrides
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~6 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The dependency pins and intended lint exclusion have no established merge-blocking issue. Merge after normal checks. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches✨ Simplify code
Comment |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The narrow dependency updates match their override ranges, with no blocking issues identified.
Review effort: Balanced
Findings: None
What changed in this PR
Updates transitive dependencies in the site's development tooling to address the reported Dependabot alerts.
Changes:
- Tightens
js-yamlto~5.4.1and adds amarkdown-itoverride of~14.3.1. - Updates locked versions to 5.4.2 and 14.3.2, retaining their existing major versions.
| File | Description |
|---|---|
| package.json | Sets patched dependency override ranges. |
| package-lock.json | Updates both resolved versions and integrity hashes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
Dependabot alerts #74 and #73 flag transitive lockfile pins with no open Dependabot PRs:
markdown-itbelow 14.3.1, andjs-yaml5.0.0–5.4.0. The site already overridesjs-yamlto>=4.2.0, which still allowed the vulnerable 5.2.2 pin frommarkdownlint-cli2. This tightens those overrides on the current major lines so the lockfile installs patched 14.3.x and 5.4.x.Changes
markdown-itto~14.3.1(installed 14.3.2).js-yamlto~5.4.1(installed 5.4.2), replacing>=4.2.0.node_modules/markdown-itandnode_modules/js-yamllockfile pins. Direct dependents still declare older versions; the overrides replace the resolved packages._org_profile/**in markdownlint so the teaching-content workflow, which is triggered bypackage-lock.json, does not fail on the org-profile README's bold subtitle (MD036). The README itself is unchanged.markdown-it15, andjs-yaml6 stay deferred).Testing
npm ci --no-fund --no-audit --ignore-scriptsnpm ls markdown-it js-yaml --allreportsmarkdown-it@14.3.2 overriddenandjs-yaml@5.4.2 overriddennpm test -- --runInBand: 20 suites, 166 tests passednpx markdownlint-cli2 --config .markdownlint-cli2.jsonc "_teaching/**/*.md" "assets/images/teaching/README.md": 0 issuespurge-website-cache,browser-security,sync-cloudflare-security-headerspassedscripts/build.shis not run locally (Ruby 3.4.10 is not installed in this environment); the PRbuildjob covers itSummary by CodeRabbit