Skip to content

Conversation

@pyyupsk
Copy link

@pyyupsk pyyupsk commented Dec 4, 2025

Initial checklist

  • I read the support docs
  • I read the contributing guide
  • I agree to follow the code of conduct
  • I searched issues and discussions and couldn't find anything or linked relevant results below
  • I made sure the docs are up to date
  • I included tests (or that's not needed)

Description of changes

Update mdast-util-to-hast minimum version from ^13.0.0 to ^13.2.1 to fix security vulnerability GHSA-4fh9-h7wg-q85m (unsanitized class attribute).

Address security vulnerability GHSA-4fh9-h7wg-q85m (unsanitized class
attribute). Update tests to use ts-ignore for runtime behavior tests.
@github-actions github-actions bot added the 👋 phase/new Post is being triaged automatically label Dec 4, 2025
@github-actions

This comment has been minimized.

@github-actions github-actions bot added 🤞 phase/open Post is being triaged manually and removed 👋 phase/new Post is being triaged automatically labels Dec 4, 2025
@ChristianMurphy
Copy link
Member

The security fix is already in range, no change is needed here, update your lockfile to get it.

@github-actions
Copy link

github-actions bot commented Dec 4, 2025

Hi! This was closed. Team: If this was merged, please describe when this is likely to be released. Otherwise, please add one of the no/* labels.

@pyyupsk pyyupsk deleted the fix/mdast-util-to-hast-security branch December 4, 2025 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🤞 phase/open Post is being triaged manually

Development

Successfully merging this pull request may close these issues.

2 participants