Skip to content

Fix vulnerable lint dependencies - #171

Merged
bvolpato merged 2 commits into
masterfrom
bvolpato/update-brace-expansion
Oct 11, 2026
Merged

bvolpato merged 2 commits into
masterfrom
bvolpato/update-brace-expansion

Conversation

@bvolpato

@bvolpato bvolpato commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The lint tooling dependency tree contains vulnerable versions of brace-expansion and KaTeX. Update both so a clean install has no npm audit findings.

Changes

  • Update the locked brace-expansion dependency from 5.0.9 to 5.0.12.
  • Override KaTeX under micromark-extension-math to 0.18.2, which fixes GHSA-238p-pmpm-9mq7. The extension's declared ^0.16.0 range excludes the security fix.
  • Update the corresponding registry URLs and integrity checksums.

Testing

Validated locally with Node.js 22.22.2 and npm 10.9.7:

  • npm ci --ignore-scripts: clean install succeeds.
  • npm run lint:all: passes.
  • npm audit --audit-level=low: zero vulnerabilities.
  • npm ls katex micromark-extension-math brace-expansion: confirms the patched versions and scoped override.
  • Smoke checks pass for ESLint Markdown parsing with math enabled, micromark inline/display math rendering, and invalid-command handling with errors enabled and disabled.
  • git diff --check: passes.

@bvolpato
bvolpato force-pushed the bvolpato/update-brace-expansion branch from da9eed8 to 5f22eb8 Compare October 11, 2026 02:11
@bvolpato bvolpato changed the title Update brace-expansion to 5.0.12 Fix vulnerable lint dependencies Oct 11, 2026
@bvolpato
bvolpato merged commit 2df18c5 into master Oct 11, 2026
6 checks passed
@bvolpato
bvolpato deleted the bvolpato/update-brace-expansion branch October 11, 2026 03:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant