Conversation
typedoc already allows markdown-it 14.3.2, which requires the patched linkify-it release and includes the related linkify denial-of-service fixes. Co-authored-by: Cursor <cursoragent@cursor.com>
Collaborator
Author
|
solved using dependabots |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves CVE-2026-59887 / GHSA-v245-v573-v5vm in
linkify-it(quadratic CPU use in themailto:validator, fixed in 5.0.2). The installed 5.0.1 copy is a docs-only transitive dependency of TypeDoc and is not part of the React Native runtime.Dependency path
Immediate parent:
markdown-it. High-level parent:typedoc. One installed version, requested aslinkify-it@^5.0.1.CVE-2026-48801 / GHSA-22p9-wv53-3rq4 (
<= 5.0.0, fixed in 5.0.1) does not apply to the installed 5.0.1 release.Package-only investigation
yarn up -R linkify-itcan resolvelinkify-it@5.0.2inside the existing^5.0.1range and changes only thelinkify-itlockfile entry. It leavesmarkdown-itat 14.2.0.Parent investigation
markdown-it@14.3.2is a non-breaking update inside TypeDoc's existingmarkdown-it@^14.1.1range. It requireslinkify-it@^5.0.2.markdown-it@15was not used. It is a major release (linkify-it6,entities8,argparse3, removed internal exports).typedoc@0.28.20was not required; its range already allows 14.3.2, and that TypeDoc release includes unrelated feature work.yarn up -R markdown-itresolvedmarkdown-it@14.3.2andlinkify-it@5.0.2.entitiesstays at 4.5.0. Onlyyarn.lockchanged.This parent update also moves
markdown-itpast GHSA-253c-mchw-3w2r (< 14.3.1) and includes the 14.3.2 security backport. Those fixes are in markdown-it's own linkify path, separate from CVE-2026-59887.Final remediation
Lockfile-only update:
markdown-it14.2.0 → 14.3.2linkify-it5.0.1 → 5.0.2Why
Both strategies fix CVE-2026-59887 and touch only
yarn.lock. The parent update is smaller in risk than a TypeDoc or markdown-it 15 upgrade, and it also clears the related quadratic linkify issue that alinkify-it-only bump would leave inmarkdown-it@14.2.0.Validation
yarn install --immutableyarn why linkify-it→ 5.0.2 viamarkdown-it@14.3.2yarn test(22 tests passed)yarn lintyarn docs(TypeDoc markdown generation)yarn npm audit -A -Rno longer reportslinkify-itormarkdown-itScope
Limited to this
linkify-itremediation. Other audit findings are unchanged and are not part of this PR.Test plan
yarn why linkify-itshows 5.0.2 onlyyarn testyarn lintyarn docsMade with Cursor