chore: fix remaining npm audit findings with overrides#630
Conversation
Refreshed against latest master to cover advisories published through Jul 21. Resolves 20 of 47 npm audit findings including both critical ones. Remaining findings need breaking upgrades in the Docusaurus toolchain. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
✅ Deploy Preview for project-hami ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: mesutoezdil The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Warning Review limit reached
Next review available in: 59 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR aims to eliminate remaining npm audit findings that cannot be resolved via npm audit fix alone by updating a dev tool (markdownlint-cli) and introducing npm overrides for vulnerable transitive dependencies in the Docusaurus/webpack toolchain.
Changes:
- Bump
markdownlint-clifrom^0.48.0to^0.49.1. - Add npm
overridesto force patched versions ofserialize-javascriptanduuid. - Refresh
package-lock.jsonaccordingly (including patch bumps across the Docusaurus/webpack dependency graph).
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| package.json | Updates markdownlint-cli and adds security-focused npm overrides. |
| package-lock.json | Locks updated dependency graph reflecting the new markdownlint-cli and override resolutions. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
354a3e6 to
b4ac3a7
Compare
b4ac3a7 to
7b391d8
Compare
7b391d8 to
eef9988
Compare
eef9988 to
3317689
Compare
Add npm overrides scoped to the parents that need them, pinned to exact versions: js-yaml, markdown-it and run-con under markdownlint-cli, serialize-javascript under copy-webpack-plugin and css-minimizer-webpack-plugin, and uuid under sockjs. Scoping keeps unrelated subtrees on their own versions. markdownlint-cli stays at 0.48.0 and run-con at 1.3.2 because their newer releases pull deps requiring Node 22 while CI runs Node 20. npm audit now reports 0 vulnerabilities. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
3317689 to
7d87fc2
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (1)
package.json:74
- The lockfile now contains dependencies that declare Node >=20.18.1 (e.g., @easyops-cn/docusaurus-search-local's cheerio and undici). To avoid installs/builds on earlier Node 20 minors that may not be supported, consider declaring the minimum Node version in package.json. Also, these overrides are currently unversioned (apply to any future versions of the same packages); scoping the override keys to the exact package versions present in the lockfile reduces the chance of unintentionally pinning future upgrades to these transitive versions.
},
"overrides": {
"markdownlint-cli": {
"js-yaml": "4.3.0",
"markdown-it": "14.3.0",
"run-con": "1.3.2"
What
Closes the audit findings that plain
npm audit fix(#556) cannot reach, via npmoverridesscoped to the parents that need them, pinned to exact versions:markdownlint-cli->js-yaml4.3.0 (high, GHSA-52cp-r559-cp3m, GHSA-h67p-54hq-rp68),markdown-it14.3.0 (moderate, GHSA-6v5v-wf23-fmfq) andrun-con1.3.2 (1.3.3 pullsini@7, which requires Node 22+ while CI runs Node 20)copy-webpack-pluginandcss-minimizer-webpack-plugin->serialize-javascript7.0.7 (high, RCE and DoS advisories)sockjs->uuid11.1.1 (moderate, GHSA-w5hq-g745-h8pq, via webpack-dev-server); deliberately keyed by sockjs rather than nested under webpack-dev-server, so that any future dependency pulling in sockjs also gets the patched uuid instead of reintroducing the vulnerable rangeScoping keeps unrelated subtrees on their own versions (for example mermaid keeps its own uuid).
markdownlint-cliitself stays at 0.48.0 because 0.49.x declaresengines.node >=22.After this,
npm auditreports 0 vulnerabilities and no package in the tree requires Node above 20.Testing
npm run lint:mdpasses with the overridden js-yaml, markdown-it and run-connpm run build:fastpassesdocusaurus startboots and serves HTTP 200 (covers the uuid override in the sockjs dev-server path)Depends on #556 (branched on top of it, both touch
package-lock.json).Part of #628