Skip to content

build(docs): override vulnerable transitive npm packages of the site - #162

Merged
indigo423 merged 1 commit into
mainfrom
fix/docs-site-npm-overrides
Oct 7, 2026
Merged

indigo423 merged 1 commit into
mainfrom
fix/docs-site-npm-overrides

Conversation

@indigo423

Copy link
Copy Markdown
Contributor

What changed

Six Dependabot alerts on website/package-lock.json, all transitive dependencies of @docusaurus/core 3.10.2 (which still pins tinypool ^1.0.2), are fixed by pinning the patched versions through the existing npm overrides block: tinypool 2.2.0, shell-quote 1.12.0, postcss-selector-parser 7.1.6, http-cache-semantics 4.3.0, source-map-js 1.2.2. Same mechanism as the existing serialize-javascript, uuid and encoding-sniffer overrides.

Not fixed: braces (GHSA-vfj7-8cjw-p6xm, regex stack exhaustion). The advisory covers every published version, including the latest 3.0.3, so no override helps. It is a dev-only glob helper used at build time.

Supersedes #159, which bumped only shell-quote in the lockfile; Dependabot closes it once this merges.

How it was verified

  • npm audit: the only remaining root advisory is braces; the 28 listed entries are its dependents.
  • make docs-urls passes with the overrides (full site build plus link check).
  • Resolved versions checked in the lockfile: shell-quote 1.12.0, tinypool 2.2.0, http-cache-semantics 4.3.0, postcss-selector-parser 7.1.6, source-map-js 1.2.2.

Checklist

  • make verify passes locally (Rust tree untouched; CI runs it).
  • Commits follow Conventional Commits and are signed off; AI-assisted commits carry an Assisted-by: trailer.
  • New source files carry the SPDX header. (none)
  • Docs updated. (not applicable)
  • New dependencies are license-compatible. (no new packages; make licenses covers the Rust tree only)
  • Breaking changes called out. (none)

🤖 Generated with Claude Code

Dependabot reports critical and high advisories in the docs site's
lockfile, all transitive dependencies of @docusaurus/core 3.10.2,
which still pins tinypool ^1.0.2: shell-quote (GHSA-pqg4-j6r4-53mv),
tinypool (GHSA-5gmw-xhrv-c9v3, GHSA-85c8-ppgw-ccpr),
http-cache-semantics (GHSA-ch52-4w7c-c8xp), source-map-js
(GHSA-68fv-2mgg-jv7q) and postcss-selector-parser
(GHSA-rj75-hqrm-r3gf). No Docusaurus release fixes them yet.

Pin each to its patched version through the existing npm overrides
block, as done before for serialize-javascript, uuid and
encoding-sniffer. The site builds and `make docs-urls` passes with
the overrides. braces (GHSA-vfj7-8cjw-p6xm) stays: the advisory covers
every published version.

Assisted-by: ClaudeCode:claude-fable-5-1
Signed-off-by: Ronny Trommer <ronny@no42.org>
@indigo423 indigo423 added the dependencies Dependency updates label Oct 7, 2026
@indigo423
indigo423 merged commit b0c196c into main Oct 7, 2026
11 checks passed
@indigo423
indigo423 deleted the fix/docs-site-npm-overrides branch October 7, 2026 21:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant