Skip to content

fix(deps): override smol-toml to ^1.8.0 to resolve GHSA-7w5x-hrqm-74c2 - #3301

Merged
devantler merged 1 commit into
mainfrom
claude/docs-smol-toml-override
Sep 10, 2026
Merged

devantler merged 1 commit into
mainfrom
claude/docs-smol-toml-override

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Summary

  • Adds "smol-toml": "^1.8.0" to the overrides field in docs/package.json.
  • Regenerates docs/package-lock.json, updating smol-toml from 1.6.1 to 1.8.0 without touching any other package.
  • Resolves high-severity vulnerability GHSA-7w5x-hrqm-74c2 (DoS via malformed TOML documents) which caused the scheduled Audit - Docs Dependencies workflow to fail on main.

Verification

  • npm audit --omit=dev --prefix docs returns 0 vulnerabilities (was exit 1 with 1 high severity vulnerability).
  • docs/scripts/audit-dependencies.sh passes (exit 0).
  • docs/scripts/audit-dependencies.test.sh passes (exit 0).
  • git diff --check passes cleanly.

Signed-off-by: Nikolai Emil Damm <nikolaiemildamm@icloud.com>
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

@devantler I will review pull request #3301.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 5e6feae5-e396-4053-a102-a3c08536f459

📥 Commits

Reviewing files that changed from the base of the PR and between a66196f and aa7328a.

⛔ Files ignored due to path filters (1)
  • docs/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • docs/package.json

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
🔇 Additional comments (1)
docs/package.json (1)

29-30: LGTM!


📝 Walkthrough

Walkthrough

The documentation package configuration adds a smol-toml override at version ^1.8.0. It also adds a trailing comma to the preceding js-yaml override.

Merge Risk: ⚪ Minimal · up to aa732

The documentation dependency is upgraded to smol-toml 1.8.0 to address the reported vulnerability, with no remaining merge-blocking risk identified.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the dependency override and the vulnerability it resolves. It accurately summarizes the main change.
Description check ✅ Passed The description accurately describes the dependency override, lockfile update, resolved vulnerability, and verification results. It is directly related to the changeset.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler
devantler marked this pull request as ready for review September 10, 2026 12:33
@devantler
devantler merged commit 57ab136 into main Sep 10, 2026
73 checks passed
@devantler
devantler deleted the claude/docs-smol-toml-override branch September 10, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant