Skip to content

Bump markdown-it and js-yaml to close Dependabot alerts #73 and #74 - #120

Merged
VatsalSy merged 2 commits into
mainfrom
rayleigh-cloud/dependabot-markdown-it-js-yaml-aeb8
Oct 5, 2026
Merged

VatsalSy merged 2 commits into
mainfrom
rayleigh-cloud/dependabot-markdown-it-js-yaml-aeb8

Conversation

@VatsalSy

@VatsalSy VatsalSy commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

Dependabot alerts #74 and #73 flag transitive lockfile pins with no open Dependabot PRs: markdown-it below 14.3.1, and js-yaml 5.0.0–5.4.0. The site already overrides js-yaml to >=4.2.0, which still allowed the vulnerable 5.2.2 pin from markdownlint-cli2. This tightens those overrides on the current major lines so the lockfile installs patched 14.3.x and 5.4.x.

Changes

  • Override markdown-it to ~14.3.1 (installed 14.3.2).
  • Override js-yaml to ~5.4.1 (installed 5.4.2), replacing >=4.2.0.
  • Refresh only the node_modules/markdown-it and node_modules/js-yaml lockfile pins. Direct dependents still declare older versions; the overrides replace the resolved packages.
  • Ignore _org_profile/** in markdownlint so the teaching-content workflow, which is triggered by package-lock.json, does not fail on the org-profile README's bold subtitle (MD036). The README itself is unchanged.
  • No major-version bumps (Babel 8, jest-dom 7, dotenv 18, jsdom, TypeScript, markdown-it 15, and js-yaml 6 stay deferred).

Testing

  • npm ci --no-fund --no-audit --ignore-scripts
  • npm ls markdown-it js-yaml --all reports markdown-it@14.3.2 overridden and js-yaml@5.4.2 overridden
  • npm test -- --runInBand: 20 suites, 166 tests passed
  • npx markdownlint-cli2 --config .markdownlint-cli2.jsonc "_teaching/**/*.md" "assets/images/teaching/README.md": 0 issues
  • Python CI tests: purge-website-cache, browser-security, sync-cloudflare-security-headers passed
  • Jekyll scripts/build.sh is not run locally (Ruby 3.4.10 is not installed in this environment); the PR build job covers it
Open in Web Open in Cursor 

Summary by CodeRabbit

  • Chores
    • Updated project maintenance settings for Markdown checks and package configuration.
    • These changes affect internal development checks and package resolution; no user-facing features or behavior have changed.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 09:46
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 38c148c4-e8dc-4060-a6e0-a15c48adbb5b
📥 Commits

Reviewing files that changed from the base of the PR and between 733fa83 and 0627b08.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • .markdownlint-cli2.jsonc
  • package.json

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: copilot-pull-request-reviewer
🔇 Additional comments (3)
.markdownlint-cli2.jsonc (1)

8-8: LGTM!

package.json (2)

48-48: LGTM!


47-47: 🗄️ Data Integrity & Integration

The v4-to-v5 compatibility warning does not identify a regression in this change. The base already resolved js-yaml 5.2.2; this change updates it to 5.4.2, so the cited v4-to-v5 API changes were already present.


📝 Walkthrough

Walkthrough

The Markdown lint configuration excludes _org_profile/**. The package overrides set js-yaml to ~5.4.1 and add markdown-it at ~14.3.1.

Changes

Markdown lint exclusion

Layer / File(s) Summary
Markdown lint exclusion
.markdownlint-cli2.jsonc
The configuration excludes Markdown files under _org_profile/** from linting.

Dependency overrides

Layer / File(s) Summary
Package dependency overrides
package.json
The js-yaml override changes to ~5.4.1, and a markdown-it override is added at ~14.3.1.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~6 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 0627b

The dependency pins and intended lint exclusion have no established merge-blocking issue. Merge after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the dependency updates and their purpose: addressing Dependabot alerts for markdown-it and js-yaml.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The narrow dependency updates match their override ranges, with no blocking issues identified.

Review effort: Balanced
Findings: None

What changed in this PR

Updates transitive dependencies in the site's development tooling to address the reported Dependabot alerts.

Changes:

  • Tightens js-yaml to ~5.4.1 and adds a markdown-it override of ~14.3.1.
  • Updates locked versions to 5.4.2 and 14.3.2, retaining their existing major versions.
File Description
package.json Sets patched dependency override ranges.
package-lock.json Updates both resolved versions and integrity hashes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 09:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The overrides and lockfile pins align, the changes are narrowly scoped, and no blocking issues remain.

Review effort: Balanced
Findings: None

@VatsalSy
VatsalSy merged commit cd9e822 into main Oct 5, 2026
6 checks passed
@VatsalSy
VatsalSy deleted the rayleigh-cloud/dependabot-markdown-it-js-yaml-aeb8 branch October 5, 2026 09:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants