Conversation
TypeDoc renders documentation with linkify enabled, and markdown-it 14.2.0 is affected by GHSA-253c-mchw-3w2r. The existing typedoc range already allows the patched 14.3.2 release. Co-authored-by: Cursor <cursoragent@cursor.com>
Collaborator
Author
|
solved using dependabots |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves the moderate
markdown-itdenial-of-service advisory GHSA-253c-mchw-3w2r (CWE-400, CWE-407). Versions below 14.3.1, including the installed 14.2.0, have two quadratic paths whenlinkify: trueis enabled. The patched 14.x release is 14.3.1; this change resolves 14.3.2, the latest 14.x release, which also backports the 15.0.2 smartquotes fix.markdown-it15.0.2 is a breaking major (linkify-itv6, removed internal subpath exports) and was not used.markdown-itis not part of the React Native runtime. It is a documentation dependency of TypeDoc. TypeDoc's defaultmarkdownItOptionssetlinkify: true, so the vulnerable option is enabled whenyarn docsruns.typographerstays off unless configured. Documentation input is repository source, so this is not an exposed runtime parser.Dependency path
Both
yarn whyentries are the same typedoc dependency (workspace instance and its virtual locator). One installed version. Immediate parent and high-level parent are bothtypedoc.Package-only investigation
typedoc@0.28.19already requestsmarkdown-it@^14.1.1, which allows 14.3.2.That resolves
markdown-it@14.3.2.markdown-it@14.3.2requireslinkify-it@^5.0.2, so the lockfile also moveslinkify-itfrom 5.0.1 to 5.0.2 and updates theentitiesdescriptor from^4.4.0to^4.5.0(still resolved at 4.5.0). Onlyyarn.lockchanges.Parent investigation
typedoc@0.28.20is the latest 0.28 patch. Its changelog has no breaking changes. It raisesmarkdown-itto^14.3.0.Tested with:
Result:
markdown-itresolved to 14.3.2. The update also pinnedtypedocto0.28.20and addedyaml@2.9.1for typedoc'syaml@^2.9.0range.^14.3.0still includes 14.3.0, which is inside the GHSA-253c-mchw-3w2r affected range, so the parent release does not itself require a fixed version. 0.28.20 was published on 2026-07-05, before this advisory.Final remediation
Lockfile-only update to
markdown-it@14.3.2.The parent update reaches the same
markdown-itversion only by floating to the newest match, and it changes TypeDoc andyamlwithout an additional security fix for this advisory. The existing range already permits 14.3.2, so the smaller lockfile change is the selected remediation.Validation
yarn install --immutableyarn why markdown-it→14.3.2viatypedoc@0.28.19(^14.1.1)yarn test --force→ 22 tests passedyarn lint→ passedyarn docs→ TypeDoc markdown generation completedyarn npm audit→ nomarkdown-itfindingyarn.lockonlyScope
This PR only remediates
markdown-it. Thelinkify-it5.0.2 resolution is required bymarkdown-it@14.3.2and is not a separate vulnerability fix. The same lockfile movement is also on open PR #243, which used amarkdown-itbump to remediatelinkify-it. These two PRs should not both be merged as-is.Made with Cursor