Skip to content

fix(deps): bump markdown-it to ^14.3.2 to address GHSA-253c-mchw-3w2r - #250

Merged
pchuri merged 1 commit into
mainfrom
fix/bump-markdown-it-ghsa-253c
Sep 30, 2026
Merged

pchuri merged 1 commit into
mainfrom
fix/bump-markdown-it-ghsa-253c

Conversation

@pchuri

@pchuri pchuri commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Description

Bumps markdown-it from ^14.1.0 (resolved 14.2.0) to ^14.3.2 to address GHSA-253c-mchw-3w2r (moderate).

With linkify: true, markdown-it <14.3.1 has two quadratic paths, so a few hundred KB of markdown can block the event loop for tens of seconds. MacroConverter.setupConfluenceMarkdownExtensions() enables linkify, so the markdown → storage path is affected.

The advisory was published after #249's PR checks ran, so the security job (npm audit --audit-level moderate --omit=dev) failed on the post-merge main run. That skipped publish and update-homebrew, and #249 has not been released yet. Merging this fix(deps) commit clears the gate and releases #249 together with this fix.

The lockfile diff only touches markdown-it and its direct dependency ranges (entities ^4.5.0, linkify-it ^5.0.2).

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Performance improvement
  • Code refactoring

Testing

  • Tests pass locally with my changes
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes

npm audit --audit-level moderate --omit=dev: found 0 vulnerabilities. npx jest: 1299 passed. npx eslint lib tests: clean.

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • Any dependent changes have been merged and published in downstream modules

markdown-it <14.3.1 with linkify enabled has two quadratic paths that
let a few hundred KB of markdown block the event loop for tens of
seconds. MacroConverter enables linkify, so markdown → storage is
exposed. The advisory also fails the release workflow's npm audit
gate, which blocked the release of #249.
@pchuri
pchuri merged commit 1df64d5 into main Sep 30, 2026
6 checks passed
@pchuri
pchuri deleted the fix/bump-markdown-it-ghsa-253c branch September 30, 2026 00:10
github-actions Bot pushed a commit that referenced this pull request Sep 30, 2026
## [2.25.4](v2.25.3...v2.25.4) (2026-09-30)

### Bug Fixes

* **deps:** bump markdown-it to ^14.3.2 to address GHSA-253c-mchw-3w2r ([#250](#250)) ([1df64d5](1df64d5)), closes [#249](#249)
* **storage-walker:** keep code blocks inside blockquotes and callouts byte-exact ([#249](#249)) ([dadfc93](dadfc93)), closes [#244](#244)
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 2.25.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant