Skip to content

chore: upgrade markdown-it to ^14.3.2 to address GHSA-253c-mchw-3w2r - #1702

Open
claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/markdown-it
Open

claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/markdown-it

Conversation

@claude

@claude claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SOU-2389

Summary

Refreshes the yarn.lock entry for the transitive dependency markdown-it from 14.2.0 to 14.3.2 (patched floor 14.3.1). It is requested via ^14.1.1 by @shikijs/markdown-it and codemirror-json-schema.

  • GHSA-253c-mchw-3w2r: two quadratic paths in linkify: true handling (rules_core/linkify and rules_inline/linkify) that can block the event loop on a few hundred KB of markdown.

The existing range already admits the patched version, so this is a lockfile-only refresh via yarn up -R markdown-it. No package.json changes or resolutions overrides. The only other lockfile change is the linkify-it descriptor key moving from ^5.0.1 to ^5.0.2, which still resolves to the already-locked 5.0.2.

Verification

  • yarn why markdown-it: every instance resolves to markdown-it@npm:14.3.2.
  • yarn workspace @sourcebot/web test: 1506 passed.

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only dependency patch for a known ReDoS-style linkify issue; no application code changes.

Overview
Bumps the locked transitive markdown-it dependency from 14.2.0 to 14.3.2 (lockfile refresh only; no package.json or resolution changes) to pick up the GHSA-253c-mchw-3w2r fix for quadratic-time linkify parsing that could stall the event loop on large markdown inputs.

The Unreleased changelog Fixed section documents the upgrade. yarn.lock also updates markdown-it’s pinned entities and linkify-it descriptor ranges as part of the resolved tree.

Reviewed by Cursor Bugbot for commit 9c91e1e. Bugbot is set up for automated code reviews on this repo. Configure here.

github-actions Bot and others added 2 commits September 30, 2026 14:29
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 42a21efd-e801-4fe8-aea9-a5bbba82a7c3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants