Repository navigation
build(docs): update sharp to 0.35.5 for GHSA-wq5f-xc86-pv6w (#2000) - #2004
Conversation
`npm audit --audit-level=high` failed the "Audit npm deps" job on the docs site: sharp 0.35.4, a transitive dependency of Astro, carries a librsvg flaw (CVE-2026-96889). `npm audit fix` moves sharp to 0.35.5 and its libvips binaries to 1.3.4; nothing else in the lockfile changes. The remaining advisories are moderate and low with no fix at the current Starlight and mermaid versions, and the job gates at high only. Fixes #2000 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Review of 65b6d0c. No finding has a line in the diff, so all four are here. Spec · spec — Issue #2000: "check the remaining moderate advisories while there." The PR body reports the check but overstates its result. It says Standards · rule — Commit message body: " Standards · rule — PR body, "How to Reproduce" step 3 and "How to Verify" step 2: "One high advisory for Standards · rule — PR body, "Impact Assessment", Duration: "Since the advisory was published, surfaced on PR #1996's audit run." names no date. Correctness — no findings. |
…hed versions scripts/audit-docs.sh says an advisory with a patched version is fixed, never accepted, by an update or an overrides entry in docs/package.json. npm reported no fix for these two because their dependents pin older majors: postcss-nested pins postcss-selector-parser ^6, and mermaid pins katex ^0.16. Both patched versions exist, so they go in as overrides, the way the block already handles js-yaml and svgo. postcss-selector-parser 7.1.6 closes GHSA-rj75-hqrm-r3gf (moderate), and katex 0.19.0 closes GHSA-238p-pmpm-9mq7 (low). npm audit now reports no advisories at any level. The docs check and build pass with them. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Answers to the review of 65b6d0c (the findings comment above), pushed as 7918347.
Fixed in 7918347:
Fixed in the squash merge message. The branch commit cannot be rewritten without a force push, which AGENTS.md step 3 rules out, and the squash merge drops the branch commits, so the subject and body passed to the merge carry the text as two sentences.
Fixed in the PR body: "One high advisory for
Fixed in the PR body: "Since 2026-10-06, when GHSA-wq5f-xc86-pv6w was published. First seen on PR #1996's audit run on 2026-10-08." Re-review of 7918347 (Standards and Correctness): no findings. Correctness confirmed postcss-nested 6.2.0 uses no API that changed in postcss-selector-parser 7, mermaid 11.17.2 calls only |
|
Review summary for 7918347.
|
Bug Description
The "Audit npm deps" job (
audit.yml) fails on the docs site.Expected:
npm audit --audit-level=highindocs/reports nothing at high or above.Actual: it reports one high advisory, GHSA-wq5f-xc86-pv6w:
sharpbelow 0.35.5, a librsvg flaw (CVE-2026-96889). Seen on PR #1996's run, which changed no lockfile.Root Cause
docs/package-lock.jsonresolvedsharp(a transitive dependency of Astro) at 0.35.4, and the advisory was published after that lock was written.Fix Description
Two commits.
npm audit fixindocs/. The lockfile movessharpto 0.35.5 and its@img/sharp-libvips-*binaries to 1.3.4. Nothing else changes in that commit.scripts/audit-docs.shsays an advisory with a patched version is fixed, by an update or anoverridesentry. Sodocs/package.jsongains two overrides, the way its block already handlesjs-yamlandsvgo:postcss-selector-parser7.1.6 closes GHSA-rj75-hqrm-r3gf (moderate), reached through@astrojs/starlight→expressive-code→postcss-nested, which pins^6.katex0.19.0 closes GHSA-238p-pmpm-9mq7 (low), reached throughmermaid, which pins^0.16.After both,
npm auditreports no advisories at any level.How to Reproduce (Before Fix)
cd docs && npm cinpm audit --audit-level=highsharp, and exit code 1.How to Verify (After Fix)
cd docs && npm cinpm auditreports 0 vulnerabilities, and exits 0../scripts/audit-docs.shpasses.npm run check && npm run buildpass (verified locally: 0 errors, 87 pages built, with the PNG to WebP conversion exercising sharp).Impact Assessment
sharp,katex, andpostcss-selector-parserrun only at docs build time. The failure is in CI's audit job.Regression Risk
Patch bump of a build-time image library, plus two overrides that lift a CSS selector parser one major and KaTeX three minors above what their dependents pin. The docs check and build pass with all three, and mermaid uses KaTeX only for math inside diagrams, which the docs do not use.
Checklist
Related Issues
Fixes #2000
🤖 Generated with Claude Code